This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] I might've recieved a virus.

11 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

A few hours ago I was browsing the web and clicked on a website. Right when I entered it, I received a notice from AntiVir saying I there was a malicious file of some sort in my Firefox directory. I had the option set to "Deny Access" and clicked "ok."
I wanna make sure my computer is still virus-free since I'm not all that assured that the virus I got was deleted.
Here's my Hijack log:



Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 7:07:49 PM, on 1/12/2010
Platform: Unknown Windows (WinNT 6.01.3504)
MSIE: Internet Explorer v8.00 (8.00.7600.16385)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files (x86)\Steam\steam.exe
C:\Program Files (x86)\AIM\aim.exe
C:\Program Files (x86)\Video Web Camera\traybar.exe
C:\Program Files (x86)\Cyberlink\Power2Go\CLMLSvc.exe
C:\Program Files (x86)\Cyberlink\PowerDVD8\PDVD8Serv.exe
C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
C:\Program Files (x86)\iTunes\iTunesHelper.exe
C:\Program Files (x86)\Video Web Camera\CEC_MAIN.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\program files (x86)\avira\antivir desktop\avcenter.exe
C:\Program Files (x86)\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://homepage.gateway.com/rdr.aspx?b=ACG…e0z1l5a4841v383
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://homepage.gateway.com/rdr.aspx?b=ACG…e0z1l5a4841v383
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://homepage.gateway.com/rdr.aspx?b=ACG…e0z1l5a4841v383
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://homepage.gateway.com/rdr.aspx?b=ACG…e0z1l5a4841v383
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Partner BHO Class - {83FF80F4-8C74-4b80-B5BA-C8DDD434E5C4} - C:\ProgramData\Partner\Partner.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.4.4525.1752\swg.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Camera Assistant Software] "C:\Program Files (x86)\Video Web Camera\traybar.exe"
O4 - HKLM\..\Run: [CLMLServer] "c:\Program Files (x86)\Cyberlink\Power2Go\CLMLSvc.exe"
O4 - HKLM\..\Run: [RemoteControl8] "c:\Program Files (x86)\CyberLink\PowerDVD8\PDVD8Serv.exe"
O4 - HKLM\..\Run: [PDVD8LanguageShortcut] "c:\Program Files (x86)\CyberLink\PowerDVD8\Language\Language.exe"
O4 - HKLM\..\Run: [avgnt] "C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe" /min
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
O4 - HKLM\..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent
O4 - HKCU\..\Run: [swg] "C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKCU\..\Run: [Steam] "c:\program files (x86)\steam\steam.exe" -silent
O4 - HKCU\..\Run: [Aim] "C:\Program Files (x86)\AIM\aim.exe" /d locale=en-US
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~2\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Google Sidewiki… - res://C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html
O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~2\Office12\REFIEBAR.DLL
O13 - Gopher Prefix:
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files (x86)\Bonjour\mDNSResponder.exe
O23 - Service: Dragon Age: Origins - Content Updater (DAUpdaterSvc) - BioWare - C:\Program Files (x86)\Dragon Age\bin_ship\DAUpdaterSvc.Service.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: Acer ePower Service (ePowerSvc) - Acer Incorporated - C:\Program Files\Gateway\Gateway Power Management\ePowerSvc.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: GameConsoleService - WildTangent, Inc. - C:\Program Files (x86)\Gateway Games\Gateway Game Console\GameConsoleService.exe
O23 - Service: GRegService (Greg_Service) - Acer Incorporated - C:\Program Files (x86)\Gateway\Registration\GregHSRW.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Intel® Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTMon.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)
O23 - Service: O2FLASH - Unknown owner - C:\Windows\system32\DRIVERS\o2flash.exe (file missing)
O23 - Service: Partner Service - Google Inc. - C:\ProgramData\Partner\Partner.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: Updater Service - Acer - C:\Program Files\Gateway\Gateway Updater\UpdaterService.exe
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

–
End of file - 10439 bytes
Hello and :welcome: Please be advised, as I am still in training, all my replies to you will be checked for accuracy by one of our experts to ensure that I am giving you the best possible advise. This may cause a delay, but I will do my best to keep it as short as possible. I am checking over your log , I will post back shortly with instructions.
Hi,

:welcome:

I will be helping you on removing malwares on your computer. Log research takes time, so please be patient and I'd be grateful if you would note the following:
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Do not install/uninstall anything on your computer unless advised.
  • Do not run any other scanning tools other than those instructed for you to use.
  • Follow the instructions on the order they are given.
  • Stay with this thread until advised when your computer is clean. Absence of symptoms does not necessarily mean a clean computer.
  • If you are being helped regarding this problem on another forum please advice us so that we can close this thread.
  • And lastly, if you have any questions, please ask before proceeding with any of the advised fixes.

_________________________________________________



If you are using Vista or Windows 7, you will need to right click and choose "Run as Administrator" to run the tools we will use.


Please download DDS by sUBs from one of the following links and save it to your desktop.
    • DDS.scr
    • DDS.pif
  • Disable any script blocking protection (How to Disable your Security Programs)
  • Right click DDS icon and choose "Run as Administrator" to run the tool (may take up to 3 minutes to run)
  • When done, DDS.txt will open.
  • After a few moments, attach.txt will open in a second window.
  • Save both reports to your desktop.
—————————————————
  • Post the contents of the DDS.txt report in your next reply
  • Attach the Attach.txt report to your post by scroling down to the Attachments area and then clicking Browse. Browse to where you saved the file, and click Open and then click UPLOAD.
—————————————————

Please include the contents of the following in your next reply:

DDS.txt

Please attach the second file; Attach.txt. To attach a file, do the following:
  • Under the reply panel is the Attachments Panel.
  • Browse for the attachment file you want to upload, then click the green Upload button.
  • Once it has uploaded, click the Manage Current Attachments drop down box.
  • Click on to insert the attachment into your post
Please post both DDS logs in your next reply.

–Next–

Download the GMER Rootkit Scanner. Unzip it to your Desktop.

Before scanning, make sure all other running programs are closed and no other actions like a scheduled antivirus scan will occur while the scan is being performed. Do not use your computer for anything else during the scan.

Right-click gmer.exe and choose "Run as Administrator". The program will begin to run.

**Caution**
These types of scans can produce false positives. Do NOT take any action on any
"<— ROOKIT" entries unless advised!

If possible rootkit activity is found, you will be asked if you would like to perform a full scan.
  • Click NO
  • In the right panel, you will see a bunch of boxes that have been checked … leave everything checked and ensure the Show all box is un-checked.
  • Now click the Scan button.
    Once the scan is complete, you may receive another notice about rootkit activity.
  • Click OK.
  • GMER will produce a log. Click on the [Save..] button, and in the File name area, type in "GMER.txt"
  • Save it where you can easily find it, such as your desktop.
If you do not receive notice about possible rootkit activity remain on the Rootkit/Malware tab & make sure the 'Show All' button is unticked.
  • Click the Scan button and let the program do its work. GMER will produce a log. Click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop
To post in your next reply:
1. DDS logs.
2. GMER log.
3. Please describe in detail any problems your computer is having.
DDS (Ver_09-12-01.01) - NTFSX64 Run by [removed] at 22:18:39.27 on Sun 01/17/2010 Internet Explorer: 8.0.7600.16385 Microsoft Windows 7 Home Premium 6.1.7600.0.1252.1.1033.18.4091.2772 [GMT -8:00] ============== Running Processes =============== C:\Windows\system32\wininit.exe C:\Windows\system32\lsm.exe C:\Windows\system32\svchost.exe -k DcomLaunch C:\Windows\system32\nvvsvc.exe C:\Windows\system32\svchost.exe -k RPCSS C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted C:\Windows\system32\svchost.exe -k netsvcs C:\Windows\system32\svchost.exe -k LocalService C:\Windows\system32\svchost.exe -k NetworkService C:\Windows\system32\nvvsvc.exe C:\Windows\System32\spoolsv.exe C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe C:\Program Files (x86)\Bonjour\mDNSResponder.exe C:\Program Files\Gateway\Gateway Power Management\ePowerSvc.exe C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation C:\Program Files (x86)\Gateway\Registration\GregHSRW.exe C:\Windows\system32\svchost.exe -k HsfXAudioService C:\Windows\system32\DRIVERS\o2flash.exe C:\Program Files\Gateway\Gateway Updater\UpdaterService.exe C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTMon.exe C:\Windows\System32\svchost.exe -k secsvcs C:\Program Files\Windows Media Player\wmpnetwk.exe C:\Windows\system32\SearchIndexer.exe C:\Windows\system32\wbem\wmiprvse.exe C:\Windows\system32\taskhost.exe C:\Windows\system32\Dwm.exe C:\Windows\Explorer.EXE C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe C:\Program Files\Synaptics\SynTP\SynTPEnh.exe C:\Program Files\Gateway\Gateway Power Management\ePowerTray.exe C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe C:\Program Files (x86)\Steam\steam.exe C:\Program Files (x86)\AIM\aim.exe C:\Windows\system32\wbem\unsecapp.exe C:\Program Files (x86)\Video Web Camera\traybar.exe C:\Program Files (x86)\Cyberlink\Power2Go\CLMLSvc.exe C:\Program Files (x86)\Cyberlink\PowerDVD8\PDVD8Serv.exe C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe C:\Program Files\Gateway\Gateway Power Management\ePowerEvent.exe C:\Program Files (x86)\iTunes\iTunesHelper.exe C:\Program Files\Synaptics\SynTP\SynTPHelper.exe C:\Program Files (x86)\Video Web Camera\CEC_MAIN.exe C:\Program Files (x86)\Common Files\Steam\SteamService.exe C:\Program Files\iPod\bin\iPodService.exe C:\Windows\System32\svchost.exe -k LocalServicePeerNet C:\Windows\system32\taskhost.exe C:\Program Files (x86)\Mozilla Firefox\firefox.exe C:\Windows\system32\SearchProtocolHost.exe C:\Windows\system32\SearchFilterHost.exe c:\program files\windows defender\MpCmdRun.exe C:\Windows\system32\DllHost.exe C:\Windows\system32\DllHost.exe C:\Users\pchiu\Desktop\dds.scr C:\Windows\system32\conhost.exe C:\Windows\system32\wbem\wmiprvse.exe ============== Pseudo HJT Report =============== uStart Page = hxxp://homepage.gateway.com/rdr.aspx?b=ACGW&l=0409&m=p-79&r=27361209p4b6l03e0z1l5a4841v383 uDefault_Page_URL = hxxp://homepage.gateway.com/rdr.aspx?b=ACGW&l=0409&m=p-79&r=27361209p4b6l03e0z1l5a4841v383 mDefault_Page_URL = hxxp://homepage.gateway.com/rdr.aspx?b=ACGW&l=0409&m=p-79&r=27361209p4b6l03e0z1l5a4841v383 mStart Page = hxxp://homepage.gateway.com/rdr.aspx?b=ACGW&l=0409&m=p-79&r=27361209p4b6l03e0z1l5a4841v383 mLocal Page = c:\windows\syswow64\blank.htm BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files (x86)\common files\adobe\acrobat\activex\AcroIEHelperShim.dll BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File BHO: Partner BHO Class: {83ff80f4-8c74-4b80-b5ba-c8ddd434e5c4} - c:\programdata\partner\Partner.dll BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files (x86)\common files\microsoft shared\windows live\WindowsLiveLogin.dll BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files (x86)\google\google toolbar\GoogleToolbar_32.dll BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files (x86)\google\googletoolbarnotifier\5.4.4525.1752\swg.dll TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files (x86)\google\google toolbar\GoogleToolbar_32.dll uRun: [swg] "c:\program files (x86)\google\googletoolbarnotifier\GoogleToolbarNotifier.exe" uRun: [Steam] "c:\program files (x86)\steam\steam.exe" -silent uRun: [Aim] "c:\program files (x86)\aim\aim.exe" /d locale=en-US mRun: [Adobe Reader Speed Launcher] "c:\program files (x86)\adobe\reader 9.0\reader\Reader_sl.exe" mRun: [Camera Assistant Software] "c:\program files (x86)\video web camera\traybar.exe" mRun: [CLMLServer] "c:\program files (x86)\cyberlink\power2go\CLMLSvc.exe" mRun: [RemoteControl8] "c:\program files (x86)\cyberlink\powerdvd8\PDVD8Serv.exe" mRun: [PDVD8LanguageShortcut] "c:\program files (x86)\cyberlink\powerdvd8\language\Language.exe" mRun: [avgnt] "c:\program files (x86)\avira\antivir desktop\avgnt.exe" /min mRun: [Adobe ARM] "c:\program files (x86)\common files\adobe\arm\1.0\AdobeARM.exe" mRun: [QuickTime Task] "c:\program files (x86)\quicktime\QTTask.exe" -atboottime mRun: [iTunesHelper] "c:\program files (x86)\itunes\iTunesHelper.exe" mPolicies-explorer: NoActiveDesktop = 1 (0x1) mPolicies-explorer: ForceActiveDesktopOn = 0 (0x0) mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5) mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3) mPolicies-system: EnableUIADesktopToggle = 0 (0x0) IE: E&xport to Microsoft Excel - c:\progra~2\micros~2\office12\EXCEL.EXE/3000 IE: Google Sidewiki… - c:\program files (x86)\google\google toolbar\component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files (x86)\windows live\writer\WriterBrowserExtension.dll IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~2\micros~2\office12\ONBttnIE.dll IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~2\micros~2\office12\REFIEBAR.DLL BHO-X64: Partner BHO Class: {83FF80F4-8C74-4b80-B5BA-C8DDD434E5C4} - c:\programdata\partner\Partner64.dll BHO-X64: Google Toolbar Helper: {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files (x86)\google\google toolbar\GoogleToolbar_64.dll BHO-X64: Google Toolbar Notifier BHO: {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - c:\program files\google\googletoolbarnotifier\5.4.4525.1752\swg64.dll TB-X64: Google Toolbar: {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files (x86)\google\google toolbar\GoogleToolbar_64.dll mRun-x64: [IAAnotif] c:\program files (x86)\intel\intel matrix storage manager\iaanotif.exe mRun-x64: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup mRun-x64: [RtHDVCpl] c:\program files\realtek\audio\hda\RAVCpl64.exe -s mRun-x64: [SynTPEnh] %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe mRun-x64: [Acer ePower Management] c:\program files\gateway\gateway power management\ePowerTray.exe mRun-x64: [Start WingMan Profiler] c:\program files\logitech\gaming software\LWEMon.exe /noui ================= FIREFOX =================== FF - ProfilePath - c:\users\pchiu\appdata\roaming\mozilla\firefox\profiles\3ofq8aor.default\ FF - prefs.js: browser.startup.homepage - hxxp://att.my.yahoo.com/ FF - component: c:\users\pchiu\appdata\roaming\mozilla\firefox\profiles\3ofq8aor.default\extensions\{81bf1d23-5f17-408d-ac6b-bd6df7caf670}\components\XpcomOpusConnector.dll FF - plugin: c:\program files (x86)\mozilla firefox\plugins\npdnu.dll FF - plugin: c:\program files (x86)\mozilla firefox\plugins\npdnupdater2.dll FF - plugin: c:\program files (x86)\windows live\photo gallery\NPWLPG.dll FF - plugin: c:\users\pchiu\appdata\roaming\move networks\plugins\npqmp071505000011.dll —- FIREFOX POLICIES —- FF - user.js: network.protocol-handler.warn-external.dnupdate - false);user_pref(network.protocol-handler.warn-external.dnupdate, falsec:\program files (x86)\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true); ============= SERVICES / DRIVERS =============== R1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\drivers\vwififlt.sys [2009-7-13 59904] R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files (x86)\avira\antivir desktop\sched.exe [2009-12-25 108289] R2 AntiVirService;Avira AntiVir Guard;c:\program files (x86)\avira\antivir desktop\avguard.exe [2009-12-25 185089] R2 avgntflt;avgntflt;c:\windows\system32\drivers\avgntflt.sys [2009-12-25 74880] R2 cpuz132;cpuz132;c:\windows\system32\drivers\cpuz132_x64.sys [2009-12-25 19432] R2 ePowerSvc;Acer ePower Service;c:\program files\gateway\gateway power management\ePowerSvc.exe [2009-11-19 844320] R2 Greg_Service;GRegService;c:\program files (x86)\gateway\registration\GregHSRW.exe [2009-8-28 1150496] R2 HsfXAudioService;HsfXAudioService;c:\windows\system32\svchost.exe -k HsfXAudioService [2009-7-13 27136] R2 Updater Service;Updater Service;c:\program files\gateway\gateway updater\UpdaterService.exe [2009-10-28 240160] R3 CAXHWAZL;CAXHWAZL;c:\windows\system32\drivers\CAXHWAZL.sys [2009-11-19 292864] R3 NETw5s64;Intel® Wireless WiFi Link 5000 Series Adapter Driver for Windows 7 - 64 Bit;c:\windows\system32\drivers\NETw5s64.sys [2009-11-19 6952960] R3 O2MDRDR;O2MDRDR;c:\windows\system32\drivers\o2mdx64.sys [2009-5-7 63264] R3 O2SDRDR;O2SDRDR;c:\windows\system32\drivers\o2sdx64.sys [2009-5-7 49696] R3 yukonw7;NDIS6.2 Miniport Driver for Marvell Yukon Ethernet Controller;c:\windows\system32\drivers\yk62x64.sys [2009-5-20 393728] S3 DAUpdaterSvc;Dragon Age: Origins - Content Updater;c:\program files (x86)\dragon age\bin_ship\daupdatersvc.service.exe [2009-12-29 25832] S3 netw5v64;Intel® Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 64 Bit;c:\windows\system32\drivers\netw5v64.sys [2009-6-10 5434368] S3 Partner Service;Partner Service;c:\programdata\partner\Partner.exe [2009-10-28 332272] S3 SrvHsfHDA;SrvHsfHDA;c:\windows\system32\drivers\VSTAZL6.SYS [2009-7-13 292864] S3 SrvHsfV92;SrvHsfV92;c:\windows\system32\drivers\VSTDPV6.SYS [2009-7-13 1485312] S3 SrvHsfWinac;SrvHsfWinac;c:\windows\system32\drivers\VSTCNXT6.SYS [2009-7-13 740864] =============== Created Last 30 ================ 2010-01-13 03:07:24 0 d—–w- c:\program files (x86)\Trend Micro 2010-01-13 02:47:57 0 d—–w- c:\users\pchiu\appdata\roaming\Malwarebytes 2010-01-13 02:47:51 22104 —-a-w- c:\windows\system32\drivers\mbam.sys 2010-01-13 02:47:51 0 d—–w- c:\programdata\Malwarebytes 2010-01-13 02:47:51 0 d—–w- c:\program files (x86)\Malwarebytes' Anti-Malware 2010-01-12 23:13:23 70656 —-a-w- c:\windows\syswow64\fontsub.dll 2010-01-12 23:13:23 148480 —-a-w- c:\windows\system32\t2embed.dll 2010-01-12 23:13:23 108544 —-a-w- c:\windows\syswow64\t2embed.dll 2010-01-12 23:13:23 100864 —-a-w- c:\windows\system32\fontsub.dll 2010-01-10 04:06:25 0 d—–w- c:\program files\Logitech 2010-01-10 03:07:47 0 d—–w- c:\program files\common files\Logitech 2010-01-09 07:26:48 69464 —-a-w- c:\windows\syswow64\XAPOFX1_3.dll 2010-01-09 07:26:48 515416 —-a-w- c:\windows\syswow64\XAudio2_5.dll 2010-01-09 07:26:48 1974616 —-a-w- c:\windows\syswow64\D3DCompiler_42.dll 2010-01-07 08:02:01 34152 —-a-w- c:\windows\system32\drivers\GEARAspiWDM.sys 2010-01-07 08:02:01 126312 —-a-w- c:\windows\system32\GEARAspi64.dll 2010-01-07 08:02:01 107368 —-a-w- c:\windows\syswow64\GEARAspi.dll 2010-01-07 08:01:47 0 d—–w- c:\programdata\{0DD0EEEE-2A7C-411C-9243-1AE62F445FC3} 2010-01-07 08:01:47 0 d—–w- c:\program files\iTunes 2010-01-07 08:01:47 0 d—–w- c:\program files\iPod 2010-01-07 08:01:47 0 d—–w- c:\program files (x86)\iTunes 2010-01-07 07:55:30 0 d—–w- c:\program files\Bonjour 2010-01-07 07:55:30 0 d—–w- c:\program files (x86)\Bonjour 2010-01-07 07:55:14 0 d—–w- c:\programdata\Apple Computer 2010-01-07 07:54:58 0 d—–w- c:\program files\common files\Apple 2010-01-07 07:54:45 0 d—–w- c:\programdata\Apple 2010-01-06 07:10:07 0 d—–w- c:\users\pchiu\appdata\roaming\Red Alert 3 Demo 2010-01-06 07:04:09 0 d—–w- c:\users\pchiu\appdata\roaming\The Creative Assembly 2010-01-05 08:18:04 0 d—–w- c:\users\pchiu\appdata\roaming\Braid 2010-01-05 08:17:59 3851784 —-a-w- c:\windows\syswow64\D3DX9_39.dll 2010-01-03 05:37:29 0 d—–w- C:\Fraps 2009-12-31 18:04:37 453456 —-a-w- c:\windows\syswow64\d3dx10_42.dll 2009-12-31 18:04:37 1892184 —-a-w- c:\windows\syswow64\D3DX9_42.dll 2009-12-31 17:50:30 0 d—–w- c:\windows\syswow64\xlive 2009-12-31 17:50:30 0 d—–w- c:\program files (x86)\Microsoft Games for Windows - LIVE 2009-12-31 17:49:04 74576 —-a-w- c:\windows\system32\XAPOFX1_2.dll 2009-12-31 17:49:04 70992 —-a-w- c:\windows\syswow64\XAPOFX1_2.dll 2009-12-31 17:49:04 518480 —-a-w- c:\windows\system32\XAudio2_3.dll 2009-12-31 17:49:04 514384 —-a-w- c:\windows\syswow64\XAudio2_3.dll 2009-12-31 17:49:03 235856 —-a-w- c:\windows\syswow64\xactengine3_3.dll 2009-12-31 17:49:03 175440 —-a-w- c:\windows\system32\xactengine3_3.dll 2009-12-31 17:49:01 25936 —-a-w- c:\windows\system32\X3DAudio1_5.dll 2009-12-31 17:49:01 23376 —-a-w- c:\windows\syswow64\X3DAudio1_5.dll 2009-12-31 17:38:01 0 d—–w- c:\program files (x86)\Eidos 2009-12-30 02:50:56 0 d—–w- c:\users\pchiu\Tracing 2009-12-30 00:15:26 0 d—–w- c:\programdata\BioWare 2009-12-30 00:04:39 0 d—–w- c:\programdata\Media Center Programs 2009-12-29 23:50:41 0 d—–w- c:\program files (x86)\Dragon Age 2009-12-29 23:50:41 0 d—–w- c:\program files (x86)\common files\BioWare 2009-12-29 22:52:50 91568 —-a-w- c:\windows\system32\drivers\scdemu.sys 2009-12-29 22:52:50 0 d—–w- c:\program files (x86)\PowerISO 2009-12-29 02:30:23 0 d—–w- c:\program files (x86)\VideoLAN 2009-12-28 22:08:50 0 d—–w- c:\users\pchiu\appdata\roaming\Packard Bell 2009-12-28 08:11:24 0 d—–w- c:\users\pchiu\appdata\roaming\Ubisoft 2009-12-28 08:10:44 0 d—–w- c:\programdata\Ubisoft 2009-12-27 06:41:54 0 d—–w- c:\users\pchiu\appdata\roaming\runic games 2009-12-27 06:40:57 364824 —-a-w- c:\windows\system32\xactengine2_4.dll 2009-12-27 02:45:15 0 d—–w- c:\program files (x86)\PFPortChecker 2009-12-25 22:59:05 0 d—–w- C:\Downloads 2009-12-25 21:44:40 2048 —-a-w- c:\windows\syswow64\tzres.dll 2009-12-25 21:44:40 2048 —-a-w- c:\windows\system32\tzres.dll 2009-12-25 21:44:06 19432 —-a-w- c:\windows\system32\drivers\cpuz132_x64.sys 2009-12-25 21:44:06 0 d—–w- c:\program files\CPUID 2009-12-25 21:44:02 311808 —-a-w- c:\windows\system32\msv1_0.dll 2009-12-25 21:44:02 257024 —-a-w- c:\windows\syswow64\msv1_0.dll 2009-12-25 21:42:43 0 d—–w- c:\program files (x86)\common files\Software Update Utility 2009-12-25 21:42:16 0 d—–w- c:\programdata\AIM 2009-12-25 21:42:13 0 d—–w- c:\program files (x86)\AIM 2009-12-25 21:42:11 0 d—–w- c:\program files (x86)\common files\AOL 2009-12-25 21:42:05 699 —ha-w- C:\IPH.PH 2009-12-25 21:40:12 0 d—–w- c:\program files (x86)\BitComet 2009-12-25 08:39:29 0 d—–w- c:\program files (x86)\SpywareBlaster 2009-12-25 08:20:13 74880 —-a-w- c:\windows\system32\drivers\avgntflt.sys 2009-12-25 08:20:13 0 d—–w- c:\programdata\Avira 2009-12-25 08:20:13 0 d—–w- c:\program files (x86)\Avira 2009-12-25 07:17:53 0 d—–w- c:\program files (x86)\common files\Steam 2009-12-25 07:17:52 0 d—–w- c:\program files (x86)\Steam 2009-12-24 22:54:51 226688 ——w- c:\windows\system32\MpSigStub.exe 2009-12-24 22:52:33 0 d—–w- C:\cabs 2009-12-24 22:42:51 0 d—–w- c:\programdata\OEM_E471269A730D 2009-12-24 22:42:47 0 d—–w- c:\program files (x86)\OEM 2009-12-24 22:40:15 0 d—–w- c:\program files\Preload 2009-12-24 22:39:58 0 d-sh–w- C:\Recovery ==================== Find3M ==================== 2009-12-01 02:02:40 171144 —-a-w- c:\windows\syswow64\xliveinstall.dll 2009-12-01 02:02:38 72840 —-a-w- c:\windows\syswow64\xliveinstallhost.exe 2009-11-21 08:46:32 86016 —-a-w- c:\windows\syswow64\frapsvid.dll 2009-11-21 08:46:30 84992 —-a-w- c:\windows\system32\frapsv64.dll 2009-11-19 10:35:21 29480 —-a-w- c:\windows\syswow64\msxml3a.dll 2009-11-19 10:35:20 505128 —-a-w- c:\windows\syswow64\msvcp71.dll 2009-11-19 10:35:20 353576 —-a-w- c:\windows\syswow64\msvcr71.dll 2009-11-19 10:33:44 1066544 —-a-w- c:\windows\syswow64\MFC71.dll 2009-11-19 10:33:43 1053232 —-a-w- c:\windows\syswow64\MFC71u.dll 2009-11-19 10:32:25 0 —ha-w- c:\windows\system32\drivers\Msft_Kernel_SynTP_01009.Wdf 2009-11-19 07:22:46 64512 —-a-w- c:\windows\syswow64\msfeedsbs.dll 2009-11-19 07:22:46 5958656 —-a-w- c:\windows\syswow64\mshtml.dll 2009-11-06 18:59:54 15406728 —-a-w- c:\windows\syswow64\xlive.dll 2009-11-06 18:59:54 13642888 —-a-w- c:\windows\syswow64\xlivefnt.dll 2009-11-04 12:25:46 484128 —-a-w- c:\windows\WisMvImg.exe 2009-10-27 18:46:44 231968 —-a-w- c:\windows\ParseModule_X86.exe 2009-10-27 18:46:42 342560 —-a-w- c:\windows\ParseModule_X64.exe 2009-10-23 09:52:58 292640 —-a-w- c:\windows\PLaunch.exe 2009-10-20 14:49:51 333088 —-a-w- c:\windows\Capsule.dll 2009-07-14 05:37:38 31548 —-a-w- c:\windows\inf\perflib\0409\perfd.dat 2009-07-14 05:37:38 31548 —-a-w- c:\windows\inf\perflib\0409\perfc.dat 2009-07-14 05:37:38 291294 —-a-w- c:\windows\inf\perflib\0409\perfi.dat 2009-07-14 05:37:38 291294 —-a-w- c:\windows\inf\perflib\0409\perfh.dat 2009-07-14 04:54:24 174 –sha-w- c:\program files\desktop.ini 2009-07-14 04:54:24 174 –sha-w- c:\program files (x86)\desktop.ini 2009-07-14 01:00:34 291294 —-a-w- c:\windows\inf\perflib\0000\perfi.dat 2009-07-14 01:00:34 291294 —-a-w- c:\windows\inf\perflib\0000\perfh.dat 2009-07-14 01:00:32 31548 —-a-w- c:\windows\inf\perflib\0000\perfd.dat 2009-07-14 01:00:32 31548 —-a-w- c:\windows\inf\perflib\0000\perfc.dat 2009-06-10 20:44:08 9633792 –sha-r- c:\windows\fonts\StaticCache.dat 2009-07-14 05:12:52 245760 –sha-w- c:\windows\system32\config\systemprofile\appdata\roaming\microsoft\windows\ietldcache\index.dat 2009-07-14 01:39:53 398848 –sha-w- c:\windows\winsxs\amd64_microsoft-windows-mail-app_31bf3856ad364e35_6.1.7600.16385_none_4d4d1f2f696639a2\WinMail.exe 2009-07-14 01:14:45 396800 –sha-w- c:\windows\winsxs\x86_microsoft-windows-mail-app_31bf3856ad364e35_6.1.7600.16385_none_f12e83abb108c86c\WinMail.exe ============= FINISH: 22:19:04.92 =============== I saved the GMER.txt after the scan just as you said but it was completely blank when I opened it. Maybe because it didn't encounter anything. 📎Attach.txt
Hi,

You have BitComet, a P2P/file sharing programs installed on your computer. P2P applications like it are the largest source of malware we see. You'll be doing yourself a favor by removing it.

P2P (File Sharing ) programs form a direct conduit onto your computer, their security measures are easily circumvented, and Malware writers are increasingly exploiting them to spread their wares onto your computer. Further to that, if your P2P program is not configured correctly you may be sharing more files than you realize. There have been cases where people's Passwords, Address Books and other personal, private, and financial details have been exposed to the file sharing network by a badly configured program.

Many of the programs come bundled with other unwanted programs, but even the ones free of any bundled software are not safe to use.

This article from InfoWorld illustrates the dangers of a poorly configured P2P program.
http://www.infoworld.com/article/07/09/06/…ID-theft_1.html

When you use them you are downloading software from an unknown source directly onto your computer, bypassing your Firewall and Anti-Virus software. Hardly surprising then that many of these Downloads are being targeted to carry infections.

I would recommend that you uninstall BitComet, via Control Panel -> Add or Remove Programs.

However, if you do not wish to remove this program please be advised not to use the said program during the course of cleaning your machine.

–Next–

Download Rooter.exe to your desktop
  • Right click the icon then choose "Run as Administrator" to start the tool.
  • A Notepad file containing the report will open, also found at %systemdrive%\Rooter.txt. Post that here.

–Next–

Please go to the site below to scan the following files:
Virus Total

Click on Browse, and upload the following file for analysis or copy/paste the text below into the browse box:
c:\windows\WisMvImg.exe

Then click Submit. Allow the file to be scanned, and then please copy and paste the results here for me to see.
If it says already scanned – click "reanalyze now"

Repeat the procedure with the following file:
  • c:\windows\ParseModule_X86.exe
  • c:\windows\ParseModule_X64.exe
  • c:\windows\PLaunch.exe
  • c:\windows\Capsule.dll
Please post the results in your next reply.

To post in your next reply:
1. Rooter log.
2. Virus total logs.
3. Symptoms of your computer.
Rooter.exe (v1.0.2) by Eric_71 . SeDebugPrivilege granted successfully … . Windows 7 Home Edition (6.1.7600) [32_bits] - Intel64 Family 6 Model 23 Stepping 10, GenuineIntel . [wscsvc] (Security Center) RUNNING (state:4) [MpsSvc] RUNNING (state:4) Windows Firewall -> Enabled Windows Defender -> Enabled User Account Control (UAC) -> Enabled . Internet Explorer 8.0.7600.16385 Mozilla Firefox 3.5.7 (en-US) . C:\ [Fixed-NTFS] .. ( Total:286 Go - Free:138 Go ) D:\ [CD_Rom] E:\ [CD_Rom] . Scan : 11:47.41 Path : C:\Users\pchiu\Desktop\Rooter.exe User : pchiu ( Administrator -> YES ) . ———————-\\ Processes . Locked [System Process] (0) Locked System (4) ______ ???n?????? (384) ______ ???n?????? (520) ______ ???n?????? (572) ______ ???n?????? (608) ______ ???n?????? (644) ______ ???n?????? (656) ______ ???n?????? (664) ______ ???n?????? (756) ______ ???n?????? (836) ______ ???n?????? (892) ______ ???n?????? (956) ______ ???n?????? (984) ______ ???n?????? (1020) ______ ???n?????? (420) ______ ???n?????? (1060) ______ ???n?????? (1172) ______ ???n?????? (1304) ______ ???n?????? (1432) ______ C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (1460) ______ ???n?????? (1480) ______ C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (1608) ______ C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe (1648) ______ C:\Program Files (x86)\Bonjour\mDNSResponder.exe (1668) ______ ???n?????? (1712) ______ ???n?????? (1760) ______ C:\Program Files (x86)\Gateway\Registration\GregHSRW.exe (1784) ______ ???n?????? (1844) ______ C:\Windows\system32\DRIVERS\o2flash.exe (1868) ______ C:\Program Files\Gateway\Gateway Updater\UpdaterService.exe (1932) ______ C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTMon.exe (2008) ______ ???n?????? (1272) ______ ???n?????? (2088) ______ ???n?????? (2120) ______ C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe (2588) ______ ???n?????? (2616) ______ ???n?????? (2624) ______ ???n?????? (2636) ______ C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (2720) ______ C:\Program Files (x86)\Steam\steam.exe (2768) ______ C:\Program Files (x86)\AIM\aim.exe (2856) ______ C:\Program Files (x86)\Video Web Camera\traybar.exe (2308) ______ C:\Program Files (x86)\Cyberlink\Power2Go\CLMLSvc.exe (2672) ______ C:\Program Files (x86)\Cyberlink\PowerDVD8\PDVD8Serv.exe (1220) ______ ???n?????? (2316) ______ C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (2760) ______ ???n?????? (1212) ______ ???n?????? (3092) ______ C:\Program Files (x86)\iTunes\iTunesHelper.exe (3104) ______ ???n?????? (3152) ______ C:\Program Files (x86)\Video Web Camera\CEC_MAIN.exe (3240) ______ ???n?????? (3512) ______ ???n?????? (3520) ______ C:\Program Files (x86)\Common Files\Steam\SteamService.exe (3632) ______ ???n?????? (4004) ______ ???n?????? (2904) ______ C:\Program Files (x86)\Mozilla Firefox\firefox.exe (1132) ______ ???n?????? (2712) Locked audiodg.exe (3060) ______ ???n?????? (3816) ______ ???n?????? (1328) ______ C:\Users\pchiu\Desktop\Rooter.exe (2952) . ———————-\\ Device\Harddisk0\ . \Device\Harddisk0 [Sectors : 63 x 512 Bytes] . \Device\Harddisk0\Partition1 (Start_Offset:1048576 | Length:12582912000) \Device\Harddisk0\Partition2 –[ MBR ]– (Start_Offset:12583960576 | Length:104857600) \Device\Harddisk0\Partition3 (Start_Offset:12688818176 | Length:307383066624) . ———————-\\ Scheduled Tasks . C:\Windows\Tasks\SA.DAT C:\Windows\Tasks\SCHEDLGU.TXT . ———————-\\ Registry . . ———————-\\ Files & Folders . ———————-\\ Scan completed at 11:47.42 . C:\Rooter$\Rooter_2.txt - (18/01/2010 | 11:47.42) File WisMvImg.exe received on 2010.01.18 19:25:51 (UTC) Antivirus Version Last Update Result a-squared 4.5.0.50 2010.01.18 - AhnLab-V3 5.0.0.2 2010.01.18 - AntiVir 7.9.1.142 2010.01.18 - Antiy-AVL 2.0.3.7 2010.01.18 - Authentium 5.2.0.5 2010.01.18 - Avast 4.8.1351.0 2010.01.18 - AVG 9.0.0.730 2010.01.18 - BitDefender 7.2 2010.01.18 - CAT-QuickHeal 10.00 2010.01.18 - ClamAV 0.94.1 2010.01.18 - Comodo 3626 2010.01.18 - DrWeb 5.0.1.12222 2010.01.18 - eSafe 7.0.17.0 2010.01.18 - eTrust-Vet 35.2.7243 2010.01.18 - F-Prot 4.5.1.85 2010.01.17 - F-Secure 9.0.15370.0 2010.01.18 - Fortinet 4.0.14.0 2010.01.18 - GData 19 2010.01.18 - Ikarus T3.1.1.80.0 2010.01.18 - Jiangmin 13.0.900 2010.01.18 - K7AntiVirus 7.10.950 2010.01.18 - Kaspersky 7.0.0.125 2010.01.18 - McAfee 5865 2010.01.18 - McAfee+Artemis 5865 2010.01.18 - McAfee-GW-Edition 6.8.5 2010.01.18 - Microsoft 1.5302 2010.01.18 - NOD32 4784 2010.01.18 - Norman 6.04.03 2010.01.18 - nProtect 2009.1.8.0 2010.01.18 - Panda 10.0.2.2 2010.01.18 - PCTools 7.0.3.5 2010.01.18 - Prevx 3.0 2010.01.18 - Rising 22.31.00.04 2010.01.18 - Sophos 4.49.0 2010.01.18 - Sunbelt 3.2.1858.2 2010.01.17 - Symantec 20091.2.0.41 2010.01.18 - TheHacker [removed].155 2010.01.18 - TrendMicro 9.120.0.1004 2010.01.18 - VBA32 3.12.12.1 2010.01.17 - ViRobot 2010.1.18.2142 2010.01.18 - VirusBuster 5.0.21.0 2010.01.18 - Additional information File size: 484128 bytes MD5…: a3bee5fc07cd3845041fcb5589af2d9c SHA1..: f77d437b62762fd3b921e453e1dbc3092cb84d48 SHA256: 7e67d257857cb93031d8b5a5d5f3aa20d8dea8fffb055a7b04e62d5c4fd93575 ssdeep: 12288:+1LvMf9YVObbY66rsP1ByKQuzjOoyX9pGHNu4B2Um3:+1Lvsd/11ByKrzj
OqI4rm3
PEiD..: - PEInfo: PE Structure information

( base data )
entrypointaddress.: 0x2a729
timedatestamp…..: 0x4af172a4 (Wed Nov 04 12:25:08 2009)
machinetype…….: 0x14c (I386)

( 5 sections )
name viradd virsiz rawdsiz ntrpy md5
.text 0x1000 0x418fc 0x41a00 6.57 c13ed126ec6c02d72c5ad95b60338e5e
.rdata 0x43000 0x10d5a 0x10e00 4.72 9370cbaeeb0f4d081a8afac259a32108
.data 0x54000 0x6318 0x2600 4.03 1452276b3a76c7345b9d2cee227d7742
.rsrc 0x5b000 0x17880 0x17a00 6.50 20ca7cb793044fe1512dee79f4ea827f
.reloc 0x73000 0x80be 0x8200 4.35 38f8b807c1d4b840d22bc6d83c6dee4d

( 13 imports )
> WIMGAPI.DLL: WIMCloseHandle, WIMCreateFile, WIMGetImageInformation
> VERSION.dll: VerQueryValueW, GetFileVersionInfoW, GetFileVersionInfoSizeW
> KERNEL32.dll: FileTimeToSystemTime, SystemTimeToFileTime, InterlockedIncrement, LeaveCriticalSection, TlsGetValue, EnterCriticalSection, GlobalReAlloc, GlobalHandle, InitializeCriticalSection, TlsAlloc, TlsSetValue, LocalReAlloc, DeleteCriticalSection, TlsFree, GlobalFlags, GetModuleHandleA, SetErrorMode, FileTimeToLocalFileTime, GetFileAttributesExW, LocalFileTimeToFileTime, GetCurrentDirectoryW, GetStartupInfoW, HeapAlloc, HeapFree, HeapReAlloc, RtlUnwind, RaiseException, Sleep, ExitProcess, HeapSize, SetUnhandledExceptionFilter, GetStdHandle, GetModuleFileNameA, lstrlenA, GetEnvironmentStringsW, GetCommandLineW, SetHandleCount, GetFileType, GetStartupInfoA, HeapCreate, VirtualFree, QueryPerformanceCounter, GetTickCount, GetSystemTimeAsFileTime, TerminateProcess, UnhandledExceptionFilter, IsDebuggerPresent, GetCPInfo, GetACP, GetOEMCP, IsValidCodePage, GetConsoleCP, GetConsoleMode, LCMapStringW, VirtualAlloc, InitializeCriticalSectionAndSpinCount, GetTimeZoneInformation, LCMapStringA, GetStringTypeA, GetStringTypeW, GetLocaleInfoA, WriteConsoleA, GetConsoleOutputCP, WriteConsoleW, SetStdHandle, GetProcessHeap, SetEnvironmentVariableA, GetDiskFreeSpaceW, GetTempFileNameW, GetFileTime, SetFileTime, GetPrivateProfileIntW, GetCurrentThread, ConvertDefaultLocale, EnumResourceLanguagesW, lstrcmpA, GetLocaleInfoW, CompareStringA, InterlockedExchange, GetShortPathNameW, GetFullPathNameW, GetCurrentProcess, DuplicateHandle, GetFileSize, SetEndOfFile, UnlockFile, LockFile, ReadFile, lstrcmpiW, GetThreadLocale, GetStringTypeExW, FreeResource, GetCurrentThreadId, GlobalFindAtomW, GlobalDeleteAtom, CompareStringW, LoadLibraryA, lstrcmpW, GetVersionExA, FreeLibrary, GetProcAddress, GetModuleHandleW, LoadLibraryW, GlobalGetAtomNameW, GlobalAddAtomW, GetCurrentProcessId, SetLastError, GlobalFree, GlobalAlloc, GlobalLock, GlobalUnlock, MulDiv, MultiByteToWideChar, FlushFileBuffers, SetFilePointer, CreateFileA, WideCharToMultiByte, GetModuleFileNameW, MoveFileW, WriteFile, GetExitCodeProcess, WaitForSingleObject, CreateProcessW, GetSystemDirectoryW, RemoveDirectoryW, GetLastError, FindNextFileW, GetVolumeInformationW, DefineDosDeviceW, GetDriveTypeW, CloseHandle, GetFileSizeEx, CreateFileW, GetLocalTime, GetVersionExW, FindClose, FindFirstFileW, DeleteFileW, WritePrivateProfileStringW, GetFileAttributesW, CreateDirectoryW, CopyFileW, SetFileAttributesW, GetDiskFreeSpaceExW, GetUserDefaultLangID, GetUserGeoID, GetSystemDefaultLangID, GetSystemDefaultUILanguage, GetPrivateProfileStringW, GetWindowsDirectoryW, FindResourceW, LoadResource, LockResource, SizeofResource, InterlockedDecrement, FormatMessageW, lstrlenW, LocalAlloc, LocalFree, FreeEnvironmentStringsW
> USER32.dll: UnregisterClassW, DestroyIcon, FillRect, SystemParametersInfoW, GetMenuItemInfoW, InflateRect, ClientToScreen, LoadCursorW, GetDC, ReleaseDC, GetSysColorBrush, ShowOwnedPopups, GetMessageW, TranslateMessage, GetCursorPos, ValidateRect, CreateDialogIndirectParamW, GetNextDlgTabItem, EndDialog, PostQuitMessage, SetWindowTextW, IsDialogMessageW, SetMenuItemBitmaps, GetMenuCheckMarkDimensions, LoadBitmapW, ModifyMenuW, EnableMenuItem, CheckMenuItem, CharUpperW, RegisterWindowMessageW, SendDlgItemMessageW, SendDlgItemMessageA, IsChild, SetWindowsHookExW, CallNextHookEx, GetClassLongW, SetPropW, GetPropW, RemovePropW, GetFocus, GetWindowTextW, DispatchMessageW, BeginDeferWindowPos, EndDeferWindowPos, GetTopWindow, DestroyWindow, GetMessageTime, GetMessagePos, MapWindowPoints, TrackPopupMenu, SetForegroundWindow, GetClientRect, CreateWindowExW, GetClassInfoExW, RegisterClassW, AdjustWindowRectEx, ScreenToClient, DeferWindowPos, CallWindowProcW, PtInRect, SystemParametersInfoA, GetWindowPlacement, GetWindowRect, GetSystemMetrics, UnhookWindowsHookEx, GetClassNameW, GetSysColor, UnpackDDElParam, ReuseDDElParam, LoadMenuW, DestroyMenu, WinHelpW, SetWindowPos, SetFocus, GetActiveWindow, EqualRect, GetDlgItem, SetWindowLongW, GetDlgCtrlID, GetKeyState, SetCursor, PeekMessageW, GetCapture, ReleaseCapture, LoadAcceleratorsW, SetActiveWindow, IsWindowVisible, InvalidateRect, IsIconic, InsertMenuItemW, CreatePopupMenu, DeleteMenu, EndPaint, GetClassInfoW, IntersectRect, BeginPaint, GetWindowDC, GrayStringW, DrawTextExW, DrawTextW, GetForegroundWindow, TabbedTextOutW, OffsetRect, SetRectEmpty, CopyRect, GetMenu, BringWindowToTop, SetMenu, GetDesktopWindow, GetWindow, ShowWindow, IsWindow, TranslateAcceleratorW, GetWindowThreadProcessId, SendMessageW, GetParent, GetWindowLongW, GetLastActivePopup, IsWindowEnabled, GetMenuState, GetMenuStringW, GetMenuItemID, InsertMenuW, GetMenuItemCount, GetSubMenu, EnableWindow, UpdateWindow, MessageBoxW, PostMessageW, LoadIconW, DefWindowProcW, wsprintfW
> GDI32.dll: ScaleWindowExtEx, DeleteDC, CreatePatternBrush, GetStockObject, SetWindowExtEx, CreateSolidBrush, GetPixel, ScaleViewportExtEx, SetViewportExtEx, OffsetViewportOrgEx, SetViewportOrgEx, SelectObject, Escape, TextOutW, RectVisible, SetTextColor, GetClipBox, CreateCompatibleDC, CreateCompatibleBitmap, GetDeviceCaps, SetMapMode, SetBkMode, RestoreDC, SaveDC, GetTextExtentPoint32W, ExtTextOutW, BitBlt, CreateFontIndirectW, DeleteObject, CreateBitmap, GetObjectW, SetBkColor, PtVisible
> COMDLG32.dll: GetFileTitleW
> WINSPOOL.DRV: ClosePrinter, OpenPrinterW, DocumentPropertiesW
> ADVAPI32.dll: RegDeleteValueW, RegCreateKeyW, GetFileSecurityW, SetFileSecurityW, RegQueryValueW, RegEnumKeyW, RegDeleteKeyW, RegCloseKey, RegSetValueExW, RegCreateKeyExW, RegOpenKeyExW, RegOpenKeyW, RegQueryValueExW, RegSetValueW
> SHELL32.dll: DragFinish, SHGetFileInfoW, ExtractIconW, DragQueryFileW
> COMCTL32.dll: InitCommonControlsEx
> SHLWAPI.dll: PathFindExtensionW, PathFindFileNameW, PathStripToRootW, PathIsUNCW, PathRemoveFileSpecW
> ole32.dll: CoUninitialize, CoInitializeEx, CoSetProxyBlanket, OleRun, CoCreateInstance, CoTaskMemFree
> OLEAUT32.dll: -, -, -, -, -, -, -, -

( 0 exports )
RDS…: NSRL Reference Data Set
- trid..: Windows OCX File (46.2%)
Win64 Executable Generic (32.0%)
Win32 Executable MS Visual C++ (generic) (14.1%)
Win32 Executable Generic (3.1%)
Win32 Dynamic Link Library (generic) (2.8%) sigcheck:
publisher….: Wistron Corp.
copyright….: Wistron Corp. All rights reserved. 2009
product……: WisMoveImage
description..: WisMoveImage
original name: WisMvImg.exe
internal name: WisMvImg.exe
file version.: 1, 0, 1, 2
comments…..: n/a
signers……: Wistron Corporation
VeriSign Class 3 Code Signing 2004 CA
Class 3 Public Primary Certification Authority
signing date.: 1:25 PM 11/4/2009
verified…..: -
pdfid.: - File ParseModule_X86.exe received on 2010.01.18 19:29:04 (UTC) Antivirus Version Last Update Result a-squared 4.5.0.50 2010.01.18 - AhnLab-V3 5.0.0.2 2010.01.18 - AntiVir 7.9.1.142 2010.01.18 - Antiy-AVL 2.0.3.7 2010.01.18 - Authentium 5.2.0.5 2010.01.18 - Avast 4.8.1351.0 2010.01.18 - AVG 9.0.0.730 2010.01.18 - BitDefender 7.2 2010.01.18 - CAT-QuickHeal 10.00 2010.01.18 - ClamAV 0.94.1 2010.01.18 - Comodo 3626 2010.01.18 - DrWeb 5.0.1.12222 2010.01.18 - eSafe 7.0.17.0 2010.01.18 - eTrust-Vet 35.2.7243 2010.01.18 - F-Prot 4.5.1.85 2010.01.17 - F-Secure 9.0.15370.0 2010.01.18 - Fortinet 4.0.14.0 2010.01.18 - GData 19 2010.01.18 - Ikarus T3.1.1.80.0 2010.01.18 - Jiangmin 13.0.900 2010.01.18 - K7AntiVirus 7.10.950 2010.01.18 - Kaspersky 7.0.0.125 2010.01.18 - McAfee 5865 2010.01.18 - McAfee+Artemis 5865 2010.01.18 - McAfee-GW-Edition 6.8.5 2010.01.18 - Microsoft 1.5302 2010.01.18 - NOD32 4784 2010.01.18 - Norman 6.04.03 2010.01.18 - nProtect 2009.1.8.0 2010.01.18 - Panda 10.0.2.2 2010.01.18 - PCTools 7.0.3.5 2010.01.18 - Prevx 3.0 2010.01.18 - Rising 22.31.00.04 2010.01.18 - Sophos 4.49.0 2010.01.18 - Sunbelt 3.2.1858.2 2010.01.17 - Symantec 20091.2.0.41 2010.01.18 - TheHacker [removed].155 2010.01.18 - TrendMicro 9.120.0.1004 2010.01.18 - VBA32 3.12.12.1 2010.01.17 - ViRobot 2010.1.18.2142 2010.01.18 - VirusBuster 5.0.21.0 2010.01.18 - Additional information File size: 231968 bytes MD5…: a577f28ca591dfb728aa3970ef59b8f6 SHA1..: 5f81bc32315b40bca4f47700546ca9b9279d452e SHA256: 5226fd506ad299a78f87b0dc1b4ea3c461b5b097fe717188b77742586b6b9091 ssdeep: 3072:1Ah/bCZIGdL7tyLqlt0wWMcxQmbZ6z1KL7fqlJFuSBr+om4/wr737RKTYzF
tgBJJ:XZzdtyLqlt0w3cxf6w3fs7NrJRTYsB/
PEiD..: - PEInfo: PE Structure information

( base data )
entrypointaddress.: 0x13a74
timedatestamp…..: 0x4a1a022a (Mon May 25 02:27:54 2009)
machinetype…….: 0x14c (I386)

( 4 sections )
name viradd virsiz rawdsiz ntrpy md5
.text 0x1000 0x2849c 0x29000 6.63 931c6189bd5a15ae25a420bc61011321
.rdata 0x2a000 0x88e4 0x9000 4.78 e01621252ae5338f75d01ead1c37e8f7
.data 0x33000 0x861c 0x3000 2.83 28ab73a22c63c43f565f31ca32172b92
.rsrc 0x3c000 0x4b4 0x1000 3.77 529d40bc4a53d2982bb894aceccfd535

( 9 imports )
> KERNEL32.dll: GlobalHandle, InitializeCriticalSection, TlsAlloc, TlsSetValue, LocalReAlloc, DeleteCriticalSection, TlsFree, GlobalAddAtomW, GetVersionExA, LoadLibraryA, GlobalFindAtomW, GetCommandLineA, HeapFree, HeapReAlloc, GetSystemTimeAsFileTime, RtlUnwind, RaiseException, ExitProcess, HeapSize, Sleep, GetCPInfo, GetACP, GetOEMCP, IsValidCodePage, TerminateProcess, UnhandledExceptionFilter, SetUnhandledExceptionFilter, IsDebuggerPresent, GetStdHandle, GetModuleFileNameA, FreeEnvironmentStringsA, GetEnvironmentStrings, FreeEnvironmentStringsW, GlobalReAlloc, SetHandleCount, GetFileType, GetStartupInfoA, HeapDestroy, HeapCreate, VirtualFree, QueryPerformanceCounter, GetTickCount, LCMapStringA, LCMapStringW, VirtualAlloc, GetTimeZoneInformation, GetStringTypeA, GetStringTypeW, GetLocaleInfoA, GetConsoleCP, GetConsoleMode, GetCurrentDirectoryA, GetDriveTypeA, SetStdHandle, WriteConsoleA, GetConsoleOutputCP, WriteConsoleW, SetEnvironmentVariableA, CreateFileA, EnterCriticalSection, TlsGetValue, LeaveCriticalSection, LocalAlloc, CompareStringW, GlobalFlags, GetModuleHandleA, WritePrivateProfileStringW, GetFileTime, GetFileAttributesW, ReleaseMutex, CreateMutexW, GetCurrentProcessId, SetErrorMode, GlobalDeleteAtom, GetCurrentThread, ConvertDefaultLocale, GetVersion, EnumResourceLanguagesW, CompareStringA, InterlockedExchange, lstrcmpW, FreeLibrary, GlobalFree, GlobalAlloc, GlobalLock, GlobalUnlock, LocalFree, GetProcAddress, GetFullPathNameW, DuplicateHandle, GetFileSize, SetEndOfFile, UnlockFile, LockFile, FlushFileBuffers, SetFilePointer, WriteFile, ReadFile, LoadLibraryW, SetLastError, GetThreadLocale, FileTimeToLocalFileTime, FileTimeToSystemTime, GetLocalTime, GetCurrentThreadId, InterlockedIncrement, HeapAlloc, FormatMessageW, GetProcessHeap, InterlockedDecrement, lstrlenW, FindClose, FindNextFileW, DeleteFileW, FindFirstFileW, GetVolumeInformationW, WideCharToMultiByte, MultiByteToWideChar, CloseHandle, WaitForSingleObject, GetModuleFileNameW, CreateFileW, GetLastError, GetCurrentProcess, GetLocaleInfoW, LockResource, LoadResource, FindResourceW, GetModuleHandleW, GetCommandLineW, GetEnvironmentStringsW, SizeofResource
> USER32.dll: RegisterWindowMessageW, LoadIconW, WinHelpW, GetCapture, GetClassLongW, SetPropW, GetPropW, RemovePropW, IsWindow, GetForegroundWindow, GetDlgItem, GetTopWindow, DestroyWindow, GetMessageTime, GetMessagePos, MapWindowPoints, SetForegroundWindow, GetClientRect, GetMenu, CreateWindowExW, GetClassInfoExW, GetClassInfoW, ShowWindow, AdjustWindowRectEx, CopyRect, DefWindowProcW, CallWindowProcW, SetWindowLongW, SetWindowPos, SystemParametersInfoA, IsIconic, GetWindowPlacement, GetSystemMetrics, UnregisterClassA, CharUpperW, GetSubMenu, GetWindow, GetDlgCtrlID, GetWindowRect, GetClassNameW, PtInRect, SetWindowTextW, ClientToScreen, GrayStringW, DrawTextExW, DrawTextW, TabbedTextOutW, SetCursor, SetMenuItemBitmaps, GetMenuCheckMarkDimensions, LoadBitmapW, GetFocus, ModifyMenuW, EnableMenuItem, DestroyMenu, RegisterClassW, GetMenuItemCount, GetMenuItemID, GetMenuState, PostQuitMessage, PostMessageW, MessageBoxW, EnableWindow, IsWindowEnabled, GetLastActivePopup, GetWindowLongW, GetParent, SendMessageW, GetWindowThreadProcessId, GetWindowTextW, UnhookWindowsHookEx, GetSysColorBrush, CheckMenuItem, SetWindowsHookExW, CallNextHookEx, GetMessageW, TranslateMessage, DispatchMessageW, GetActiveWindow, IsWindowVisible, GetKeyState, PeekMessageW, GetCursorPos, ValidateRect, LoadCursorW, GetDC, ReleaseDC, GetSysColor
> GDI32.dll: Escape, GetStockObject, DeleteDC, ScaleWindowExtEx, SetWindowExtEx, ScaleViewportExtEx, SetViewportExtEx, OffsetViewportOrgEx, SetViewportOrgEx, ExtTextOutW, TextOutW, RectVisible, PtVisible, DeleteObject, GetClipBox, SetMapMode, SetTextColor, GetDeviceCaps, CreateBitmap, SaveDC, RestoreDC, SetBkColor, SelectObject
> comdlg32.dll: GetFileTitleW
> WINSPOOL.DRV: ClosePrinter, DocumentPropertiesW, OpenPrinterW
> ADVAPI32.dll: RegQueryValueW, RegEnumKeyW, RegDeleteKeyW, RegSetValueExW, RegCreateKeyExW, RegOpenKeyExW, RegOpenKeyW, RegCloseKey, CryptCreateHash, CryptAcquireContextW, CryptDecrypt, CryptDestroyKey, CryptDeriveKey, CryptHashData, CryptDestroyHash, CryptReleaseContext, RegQueryValueExW
> SHELL32.dll: CommandLineToArgvW
> SHLWAPI.dll: PathIsUNCW, PathFindExtensionW, PathFindFileNameW, PathStripToRootW
> OLEAUT32.dll: -, -, -

( 0 exports )
RDS…: NSRL Reference Data Set
- sigcheck:
publisher….: Acer Inc.
copyright….: Copyright © 2009 Acer Inc.
product……: Acer GAIA ParseModule
description..: Acer GAIA ParseModule
original name: ParseModule.exe
internal name: ParseMod
file version.: 1, 0, 0, 1
comments…..: n/a
signers……: Acer Incorporated
VeriSign Class 3 Code Signing 2004 CA
Class 3 Public Primary Certification Authority
signing date.: 3:47 AM 10/27/2009
verified…..: -
pdfid.: - trid..: Win64 Executable Generic (59.6%)
Win32 Executable MS Visual C++ (generic) (26.2%)
Win32 Executable Generic (5.9%)
Win32 Dynamic Link Library (generic) (5.2%)
Generic Win/DOS Executable (1.3%) File ParseModule_X64.exe received on 2010.01.18 19:38:52 (UTC) Antivirus Version Last Update Result a-squared 4.5.0.50 2010.01.18 - AhnLab-V3 5.0.0.2 2010.01.18 - AntiVir 7.9.1.142 2010.01.18 - Antiy-AVL 2.0.3.7 2010.01.18 - Authentium 5.2.0.5 2010.01.18 - Avast 4.8.1351.0 2010.01.18 - AVG 9.0.0.730 2010.01.18 - BitDefender 7.2 2010.01.18 - CAT-QuickHeal 10.00 2010.01.18 - ClamAV 0.94.1 2010.01.18 - Comodo 3626 2010.01.18 - DrWeb 5.0.1.12222 2010.01.18 - eSafe 7.0.17.0 2010.01.18 - eTrust-Vet 35.2.7243 2010.01.18 - F-Prot 4.5.1.85 2010.01.18 - F-Secure 9.0.15370.0 2010.01.18 - Fortinet 4.0.14.0 2010.01.18 - GData 19 2010.01.18 - Ikarus T3.1.1.80.0 2010.01.18 - Jiangmin 13.0.900 2010.01.18 - K7AntiVirus 7.10.950 2010.01.18 - Kaspersky 7.0.0.125 2010.01.18 - McAfee 5865 2010.01.18 - McAfee+Artemis 5865 2010.01.18 - McAfee-GW-Edition 6.8.5 2010.01.18 - Microsoft 1.5302 2010.01.18 - NOD32 4784 2010.01.18 - Norman 6.04.03 2010.01.18 - nProtect 2009.1.8.0 2010.01.18 - Panda 10.0.2.2 2010.01.18 - PCTools 7.0.3.5 2010.01.18 - Prevx 3.0 2010.01.18 - Rising 22.31.00.04 2010.01.18 - Sophos 4.49.0 2010.01.18 - Sunbelt 3.2.1858.2 2010.01.17 - Symantec 20091.2.0.41 2010.01.18 - TheHacker [removed].155 2010.01.18 - TrendMicro 9.120.0.1004 2010.01.18 - VBA32 3.12.12.1 2010.01.17 - ViRobot 2010.1.18.2142 2010.01.18 - VirusBuster 5.0.21.0 2010.01.18 - Additional information File size: 342560 bytes MD5…: 6222d069102d98086cfeb9876e4f980f SHA1..: a0b9e780c20e7627208f25863db45db8381d5fd9 SHA256: e10aad24c42c93d1c5520f2bcbd5d2ce696aa73b9c614f8d33df7bf4898c531e ssdeep: 6144:6CGHKIP7LO6VsLa9DrCMIMCldVFevZOoMQfp4s28koIj:LIPPO6VMCX5RCY
v+ep45jj
PEiD..: - PEInfo: PE Structure information

( base data )
entrypointaddress.: 0x1fdd0
timedatestamp…..: 0x4a1a0205 (Mon May 25 02:27:17 2009)
machinetype…….: 0x8664 (AMD64)

( 5 sections )
name viradd virsiz rawdsiz ntrpy md5
.text 0x1000 0x3a3ee 0x3a400 6.32 3011770e53ba83bad5b1c06ada7c66a8
.rdata 0x3c000 0x1010c 0x10200 4.63 5d50b5195008f9dc9fd764c7bc92ae8a
.data 0x4d000 0xb130 0x2c00 3.23 4fe87130fcaf6e4fcfbec8d957110135
.pdata 0x59000 0x4344 0x4400 5.48 da1157cb2dca18caa834033610b3c483
.rsrc 0x5e000 0x4b4 0x600 3.98 be8018397b1e4ecbce22a68d1a633b94

( 9 imports )
> KERNEL32.dll: WritePrivateProfileStringW, GlobalFlags, GetCommandLineA, HeapFree, HeapReAlloc, GetSystemTimeAsFileTime, RtlLookupFunctionEntry, RtlUnwindEx, RaiseException, RtlPcToFileHeader, ExitProcess, HeapSize, TerminateProcess, UnhandledExceptionFilter, SetUnhandledExceptionFilter, IsDebuggerPresent, RtlCaptureContext, RtlVirtualUnwind, GetCPInfo, GetACP, GetOEMCP, IsValidCodePage, FlsGetValue, FlsSetValue, FlsFree, FlsAlloc, Sleep, GetStdHandle, GetModuleFileNameA, GetEnvironmentStrings, FreeEnvironmentStringsW, GetEnvironmentStringsW, SetHandleCount, GetFileType, GetStartupInfoA, HeapSetInformation, HeapCreate, QueryPerformanceCounter, GetTickCount, LCMapStringA, LCMapStringW, GetTimeZoneInformation, GetConsoleCP, GetConsoleMode, GetStringTypeA, GetStringTypeW, GetLocaleInfoA, GetCurrentDirectoryA, GetDriveTypeA, SetStdHandle, WriteConsoleA, GetConsoleOutputCP, WriteConsoleW, SetEnvironmentVariableA, CreateFileA, GlobalAddAtomW, GlobalFindAtomW, CompareStringW, LoadLibraryA, GetVersionExA, GetModuleHandleA, TlsFree, DeleteCriticalSection, LocalReAlloc, TlsSetValue, GlobalHandle, GlobalReAlloc, TlsAlloc, InitializeCriticalSection, EnterCriticalSection, TlsGetValue, LeaveCriticalSection, LocalAlloc, GetFileTime, GetFileAttributesW, ReleaseMutex, CreateMutexW, GetCurrentProcessId, GlobalDeleteAtom, GetCurrentThread, ConvertDefaultLocale, GetVersion, EnumResourceLanguagesW, CompareStringA, lstrcmpW, FreeLibrary, SetErrorMode, GetProcAddress, GetFullPathNameW, DuplicateHandle, GetFileSize, SetEndOfFile, UnlockFile, LockFile, FlushFileBuffers, SetFilePointer, WriteFile, ReadFile, LoadLibraryW, SetLastError, GetThreadLocale, GlobalFree, GlobalAlloc, GlobalLock, GlobalUnlock, LocalFree, GetLocalTime, GetCurrentThreadId, FileTimeToLocalFileTime, FileTimeToSystemTime, HeapAlloc, FormatMessageW, GetProcessHeap, lstrlenW, DeleteFileW, GetVolumeInformationW, FindFirstFileW, WideCharToMultiByte, CloseHandle, MultiByteToWideChar, WaitForSingleObject, CreateFileW, GetModuleFileNameW, GetLastError, GetLocaleInfoW, GetCurrentProcess, FindClose, FindNextFileW, SizeofResource, LoadResource, FindResourceW, LockResource, GetModuleHandleW, FreeEnvironmentStringsA, GetCommandLineW
> USER32.dll: SetWindowTextW, SetCursor, SetMenuItemBitmaps, GetMenuCheckMarkDimensions, LoadBitmapW, ModifyMenuW, EnableMenuItem, CheckMenuItem, GetMessageW, TranslateMessage, GetActiveWindow, GetCursorPos, ValidateRect, RegisterWindowMessageW, LoadIconW, WinHelpW, GetCapture, SetWindowsHookExW, CallNextHookEx, GetClassNameW, GetClassLongPtrW, SetPropW, GetPropW, RemovePropW, GetFocus, IsWindow, GetForegroundWindow, DispatchMessageW, GetDlgItem, ShowWindow, DestroyWindow, GetWindowLongPtrW, SetWindowLongPtrW, GetMessageTime, GetMessagePos, PeekMessageW, MapWindowPoints, GetKeyState, SetForegroundWindow, UnregisterClassA, GetSubMenu, GetMenuItemCount, GetMenuItemID, IsWindowVisible, GetClientRect, GetMenu, CreateWindowExW, GetClassInfoExW, GetClassInfoW, RegisterClassW, AdjustWindowRectEx, CopyRect, PtInRect, GetDlgCtrlID, DefWindowProcW, CallWindowProcW, SetWindowPos, SystemParametersInfoA, IsIconic, GetWindowPlacement, DestroyMenu, GetTopWindow, GetMenuState, GetSystemMetrics, CharUpperW, PostQuitMessage, PostMessageW, MessageBoxW, EnableWindow, IsWindowEnabled, GetLastActivePopup, GetParent, GetWindowLongW, SendMessageW, GetWindowThreadProcessId, GetWindowTextW, GetSysColorBrush, GetSysColor, GetWindowRect, GetWindow, ClientToScreen, GrayStringW, DrawTextExW, DrawTextW, TabbedTextOutW, UnhookWindowsHookEx, LoadCursorW, GetDC, ReleaseDC
> GDI32.dll: SelectObject, GetStockObject, CreateBitmap, DeleteDC, ScaleWindowExtEx, SetWindowExtEx, ScaleViewportExtEx, SetViewportExtEx, OffsetViewportOrgEx, SetBkColor, Escape, ExtTextOutW, TextOutW, RectVisible, PtVisible, DeleteObject, GetClipBox, SetMapMode, SetTextColor, GetDeviceCaps, SaveDC, RestoreDC, SetViewportOrgEx
> comdlg32.dll: GetFileTitleW
> WINSPOOL.DRV: ClosePrinter, DocumentPropertiesW, OpenPrinterW
> ADVAPI32.dll: RegQueryValueW, RegEnumKeyW, RegDeleteKeyW, RegSetValueExW, RegCreateKeyExW, RegOpenKeyExW, RegOpenKeyW, RegCloseKey, CryptDecrypt, CryptDestroyKey, CryptDeriveKey, CryptHashData, CryptDestroyHash, CryptReleaseContext, CryptCreateHash, CryptAcquireContextW, RegQueryValueExW
> SHELL32.dll: CommandLineToArgvW
> SHLWAPI.dll: PathIsUNCW, PathFindFileNameW, PathFindExtensionW, PathStripToRootW
> OLEAUT32.dll: -, -, -

( 0 exports )
RDS…: NSRL Reference Data Set
- sigcheck:
publisher….: Acer Inc.
copyright….: Copyright © 2009 Acer Inc.
product……: Acer GAIA ParseModule
description..: Acer GAIA ParseModule
original name: ParseModule.exe
internal name: ParseMod
file version.: 1, 0, 0, 1
comments…..: n/a
signers……: Acer Incorporated
VeriSign Class 3 Code Signing 2004 CA
Class 3 Public Primary Certification Authority
signing date.: 3:47 AM 10/27/2009
verified…..: -
pdfid.: - trid..: Win64 Executable Generic (95.5%)
Generic Win/DOS Executable (2.2%)
DOS Executable Generic (2.2%)
Autodesk FLIC Image File (extensions: flc, fli, cel) (0.0%) File PLaunch.exe received on 2010.01.18 19:41:11 (UTC) Antivirus Version Last Update Result a-squared 4.5.0.50 2010.01.18 - AhnLab-V3 5.0.0.2 2010.01.18 - AntiVir 7.9.1.142 2010.01.18 - Antiy-AVL 2.0.3.7 2010.01.18 - Authentium 5.2.0.5 2010.01.18 - Avast 4.8.1351.0 2010.01.18 - AVG 9.0.0.730 2010.01.18 - BitDefender 7.2 2010.01.18 - CAT-QuickHeal 10.00 2010.01.18 - ClamAV 0.94.1 2010.01.18 - Comodo 3626 2010.01.18 - DrWeb 5.0.1.12222 2010.01.18 - eSafe 7.0.17.0 2010.01.18 - eTrust-Vet 35.2.7243 2010.01.18 - F-Prot 4.5.1.85 2010.01.18 - F-Secure 9.0.15370.0 2010.01.18 - Fortinet 4.0.14.0 2010.01.18 - GData 19 2010.01.18 - Ikarus T3.1.1.80.0 2010.01.18 - Jiangmin 13.0.900 2010.01.18 - K7AntiVirus 7.10.950 2010.01.18 - Kaspersky 7.0.0.125 2010.01.18 - McAfee 5865 2010.01.18 - McAfee+Artemis 5865 2010.01.18 - McAfee-GW-Edition 6.8.5 2010.01.18 - Microsoft 1.5302 2010.01.18 - NOD32 4784 2010.01.18 - Norman 6.04.03 2010.01.18 - nProtect 2009.1.8.0 2010.01.18 - Panda 10.0.2.2 2010.01.18 - PCTools 7.0.3.5 2010.01.18 - Prevx 3.0 2010.01.18 - Rising 22.31.00.04 2010.01.18 - Sophos 4.49.0 2010.01.18 - Sunbelt 3.2.1858.2 2010.01.17 - Symantec 20091.2.0.41 2010.01.18 - TheHacker [removed].155 2010.01.18 - TrendMicro 9.120.0.1004 2010.01.18 - VBA32 3.12.12.1 2010.01.17 - ViRobot 2010.1.18.2142 2010.01.18 - VirusBuster 5.0.21.0 2010.01.18 - Additional information File size: 292640 bytes MD5…: 94a7e53c86209433ebf01796ab066db2 SHA1..: 9596342723f1bad16f7bb0ecc5e25cd49169b025 SHA256: cb71dc552f3466474a0f6db53a018628ebf05946223876aa376296b534de92be ssdeep: 6144:fj032yROuAysupnyQpgMHoIr+b4t2mvyYe9Fag6Mh/a:fjOO8tvHoU2zZGX
F
PEiD..: - PEInfo: PE Structure information

( base data )
entrypointaddress.: 0x24fda
timedatestamp…..: 0x4ae17cdc (Fri Oct 23 09:52:28 2009)
machinetype…….: 0x14c (I386)

( 4 sections )
name viradd virsiz rawdsiz ntrpy md5
.text 0x1000 0x39096 0x39200 6.60 4026a1b3a05607830c04c667ac6b94b8
.rdata 0x3b000 0xa578 0xa600 5.21 21dd75d62fc49dbf81dd913eda08aa4a
.data 0x46000 0x5a5c 0x2000 3.95 f127cdbebd975161e9ec936f1f739726
.rsrc 0x4c000 0x4c4 0x600 4.55 d6e93eabd28deef77eee83f820d034ed

( 9 imports )
> VERSION.dll: VerQueryValueA, GetFileVersionInfoSizeA, GetFileVersionInfoA
> KERNEL32.dll: GetLocaleInfoA, GetCPInfo, GetOEMCP, HeapAlloc, HeapFree, VirtualProtect, VirtualAlloc, GetSystemInfo, VirtualQuery, RtlUnwind, Sleep, ExitProcess, GetCommandLineA, GetStartupInfoA, RaiseException, HeapReAlloc, HeapSize, GetACP, IsValidCodePage, TerminateProcess, UnhandledExceptionFilter, SetUnhandledExceptionFilter, IsDebuggerPresent, InterlockedExchange, HeapCreate, GetStdHandle, LCMapStringA, LCMapStringW, SetHandleCount, GetFileType, InitializeCriticalSectionAndSpinCount, FreeEnvironmentStringsA, GetEnvironmentStrings, FreeEnvironmentStringsW, GetEnvironmentStringsW, QueryPerformanceCounter, GetTickCount, GetSystemTimeAsFileTime, GetTimeZoneInformation, GetStringTypeA, GetStringTypeW, GetConsoleCP, GetConsoleMode, SetStdHandle, WriteConsoleA, GetConsoleOutputCP, WriteConsoleW, GetProcessHeap, CompareStringW, SetEnvironmentVariableA, GlobalFindAtomA, GlobalDeleteAtom, lstrcmpW, GlobalFlags, GlobalAddAtomA, GetFileTime, GetFileSizeEx, FileTimeToLocalFileTime, GetCurrentThreadId, FileTimeToSystemTime, lstrcmpA, GlobalGetAtomNameA, TlsFree, DeleteCriticalSection, LocalReAlloc, TlsSetValue, TlsAlloc, InitializeCriticalSection, GlobalHandle, GlobalReAlloc, EnterCriticalSection, TlsGetValue, LeaveCriticalSection, InterlockedIncrement, GetModuleHandleA, GetModuleHandleW, CompareStringA, CreateFileA, GetFullPathNameA, GetCurrentProcess, DuplicateHandle, CloseHandle, GetFileSize, SetEndOfFile, UnlockFile, LockFile, FlushFileBuffers, SetFilePointer, WriteFile, ReadFile, GetCurrentProcessId, GetLastError, SetLastError, GlobalFree, GlobalAlloc, GlobalLock, GlobalUnlock, CopyFileA, GetDriveTypeA, CreateDirectoryA, LoadLibraryA, GetProcAddress, FreeLibrary, GetModuleFileNameA, WritePrivateProfileStringA, GetVolumeInformationA, GetFileAttributesA, SetFileAttributesA, DeleteFileA, FindNextFileA, RemoveDirectoryA, GetPrivateProfileStringA, GetVersionExA, GetLocalTime, FindFirstFileA, FindClose, InterlockedDecrement, FormatMessageA, lstrlenA, LocalAlloc, LocalFree, WideCharToMultiByte, FindResourceA, LoadResource, LockResource, SizeofResource, MultiByteToWideChar, VirtualFree
> USER32.dll: DestroyMenu, PostQuitMessage, GrayStringA, DrawTextExA, DrawTextA, TabbedTextOutA, RegisterWindowMessageA, LoadIconA, WinHelpA, GetCapture, GetClassLongA, SetPropA, GetPropA, RemovePropA, GetForegroundWindow, GetTopWindow, DestroyWindow, GetMessageTime, GetMessagePos, MapWindowPoints, SetMenu, SetForegroundWindow, GetClientRect, PostMessageA, CreateWindowExA, GetClassInfoExA, GetClassInfoA, RegisterClassA, AdjustWindowRectEx, CopyRect, DefWindowProcA, CallWindowProcA, GetMenu, SystemParametersInfoA, IsIconic, GetWindowPlacement, SetMenuItemBitmaps, GetMenuCheckMarkDimensions, LoadBitmapA, ModifyMenuA, EnableMenuItem, CheckMenuItem, SetWindowPos, SetWindowLongA, IsWindow, GetDlgItem, GetFocus, ClientToScreen, GetWindow, GetDlgCtrlID, GetWindowRect, GetClassNameA, PtInRect, SetWindowTextA, SetWindowsHookExA, CallNextHookEx, DispatchMessageA, GetKeyState, PeekMessageA, ValidateRect, GetWindowTextA, UnhookWindowsHookEx, LoadCursorA, GetDC, ReleaseDC, GetSysColor, GetSysColorBrush, CharUpperA, GetSystemMetrics, GetWindowThreadProcessId, SendMessageA, GetParent, GetWindowLongA, GetLastActivePopup, IsWindowEnabled, EnableWindow, MessageBoxA, GetMenuState, GetMenuItemID, GetMenuItemCount, GetSubMenu, wsprintfA
> GDI32.dll: DeleteDC, GetStockObject, Escape, ExtTextOutA, TextOutA, RectVisible, PtVisible, ScaleWindowExtEx, SetWindowExtEx, ScaleViewportExtEx, SetViewportExtEx, OffsetViewportOrgEx, SetViewportOrgEx, DeleteObject, GetDeviceCaps, SetMapMode, RestoreDC, SaveDC, SetBkColor, SetTextColor, GetClipBox, CreateBitmap, SelectObject
> COMDLG32.dll: GetFileTitleA
> WINSPOOL.DRV: ClosePrinter, OpenPrinterA, DocumentPropertiesA
> SHLWAPI.dll: PathFindFileNameA, PathStripToRootA, PathIsUNCA
> ole32.dll: CoInitializeEx, CoCreateInstance, OleRun
> OLEAUT32.dll: -, -, -, -, -, -, -, -, -

( 0 exports )
RDS…: NSRL Reference Data Set
- pdfid.: - sigcheck:
publisher….: Wistron Corp.
copyright….: Copyright c 2006-2009
product……: PreLaunch
description..: PreLaunch
original name: PreLaunch.exe
internal name: PreLaunch
file version.: 2, 1, 0, 7
comments…..: n/a
signers……: Wistron Corporation
VeriSign Class 3 Code Signing 2004 CA
Class 3 Public Primary Certification Authority
signing date.: 10:52 AM 10/23/2009
verified…..: -
trid..: Win64 Executable Generic (59.6%)
Win32 Executable MS Visual C++ (generic) (26.2%)
Win32 Executable Generic (5.9%)
Win32 Dynamic Link Library (generic) (5.2%)
Generic Win/DOS Executable (1.3%) File Capsule.dll received on 2010.01.18 19:44:56 (UTC) Antivirus Version Last Update Result a-squared 4.5.0.50 2010.01.18 - AhnLab-V3 5.0.0.2 2010.01.18 - AntiVir 7.9.1.142 2010.01.18 - Antiy-AVL 2.0.3.7 2010.01.18 - Authentium 5.2.0.5 2010.01.18 - Avast 4.8.1351.0 2010.01.18 - AVG 9.0.0.730 2010.01.18 - BitDefender 7.2 2010.01.18 - CAT-QuickHeal 10.00 2010.01.18 - ClamAV 0.94.1 2010.01.18 - Comodo 3626 2010.01.18 - DrWeb 5.0.1.12222 2010.01.18 - eSafe 7.0.17.0 2010.01.18 Virus in password protected archive eTrust-Vet 35.2.7243 2010.01.18 - F-Prot 4.5.1.85 2010.01.18 - F-Secure 9.0.15370.0 2010.01.18 - Fortinet 4.0.14.0 2010.01.18 - GData 19 2010.01.18 - Ikarus T3.1.1.80.0 2010.01.18 - Jiangmin 13.0.900 2010.01.18 - K7AntiVirus 7.10.950 2010.01.18 - Kaspersky 7.0.0.125 2010.01.18 - McAfee 5865 2010.01.18 - McAfee+Artemis 5865 2010.01.18 - McAfee-GW-Edition 6.8.5 2010.01.18 - Microsoft 1.5302 2010.01.18 - NOD32 4784 2010.01.18 - Norman 6.04.03 2010.01.18 - nProtect 2009.1.8.0 2010.01.18 - Panda 10.0.2.2 2010.01.18 - PCTools 7.0.3.5 2010.01.18 - Prevx 3.0 2010.01.18 - Rising 22.31.00.04 2010.01.18 - Sophos 4.49.0 2010.01.18 - Sunbelt 3.2.1858.2 2010.01.17 - Symantec 20091.2.0.41 2010.01.18 - TheHacker [removed].155 2010.01.18 - TrendMicro 9.120.0.1004 2010.01.18 - VBA32 3.12.12.1 2010.01.17 - ViRobot 2010.1.18.2142 2010.01.18 - VirusBuster 5.0.21.0 2010.01.18 - Additional information File size: 333088 bytes MD5…: f145b8e5d2293c337d595521ca1d0132 SHA1..: 2a0b911b17712222932f347a777aa94493999bc9 SHA256: ce4f7746bae018dbc348b450d5489d374b08e0f67ba725761b1efdb967f7cc08 ssdeep: 6144:EF3B5JHJ3TLwK2UFT5Ug8UfRyMgTB9Zs6vFLZco:EpPnLww5U4MTTZrl
PEiD..: - PEInfo: PE Structure information

( base data )
entrypointaddress.: 0x1e543
timedatestamp…..: 0x4954d2a2 (Fri Dec 26 12:48:34 2008)
machinetype…….: 0x14c (I386)

( 5 sections )
name viradd virsiz rawdsiz ntrpy md5
.text 0x1000 0x3405d 0x35000 6.66 680c10bab8a4a97090bf79ecbc7d0c6f
.rdata 0x36000 0xd4b4 0xe000 5.57 098fceac99ddb1e09bf92250ae00d19c
.data 0x44000 0x5e40 0x3000 3.30 f12de1c37ad333e754d513903c817b51
.rsrc 0x4a000 0x2db4 0x3000 4.35 fe7811958f1de18db52e795f2e992af2
.reloc 0x4d000 0x57f2 0x6000 4.03 b907a2c330a3a69aa0ae6e589274cdda

( 8 imports )
> KERNEL32.dll: LocalReAlloc, DeleteCriticalSection, TlsFree, SetErrorMode, WritePrivateProfileStringA, GlobalFlags, InterlockedIncrement, GetVersionExA, lstrcmpW, GlobalFindAtomA, GlobalGetAtomNameA, GetCPInfo, GetOEMCP, RtlUnwind, HeapAlloc, HeapFree, HeapReAlloc, VirtualAlloc, GetCommandLineA, GetProcessHeap, GetSystemTimeAsFileTime, RaiseException, SetEnvironmentVariableA, SetCurrentDirectoryA, ExitProcess, HeapSize, TerminateProcess, UnhandledExceptionFilter, TlsSetValue, IsDebuggerPresent, SetStdHandle, GetFileType, SetHandleCount, GetStdHandle, GetStartupInfoA, Sleep, VirtualFree, HeapDestroy, HeapCreate, FreeEnvironmentStringsA, GetEnvironmentStrings, FreeEnvironmentStringsW, GetEnvironmentStringsW, QueryPerformanceCounter, GetTickCount, GetTimeZoneInformation, GetACP, IsValidCodePage, LCMapStringA, LCMapStringW, GetConsoleCP, GetConsoleMode, GetStringTypeA, GetStringTypeW, WriteConsoleA, GetConsoleOutputCP, WriteConsoleW, TlsAlloc, InitializeCriticalSection, GlobalHandle, GlobalReAlloc, EnterCriticalSection, TlsGetValue, LeaveCriticalSection, LocalAlloc, GetFileTime, SetFileTime, SystemTimeToFileTime, LocalFileTimeToFileTime, FileTimeToLocalFileTime, FileTimeToSystemTime, GetFullPathNameA, GetVolumeInformationA, FindFirstFileA, FindClose, GetCurrentProcess, DuplicateHandle, SetEndOfFile, UnlockFile, LockFile, FlushFileBuffers, ReadFile, GetThreadLocale, InterlockedDecrement, GetModuleFileNameW, GlobalFree, GlobalUnlock, GetCurrentProcessId, SetLastError, GlobalAddAtomA, GlobalDeleteAtom, GetCurrentThread, GetCurrentThreadId, ConvertDefaultLocale, EnumResourceLanguagesA, GetLocaleInfoA, LoadLibraryA, GlobalLock, lstrcmpA, GlobalAlloc, FreeLibrary, GetModuleHandleA, GetProcAddress, UnmapViewOfFile, CreateFileMappingA, MapViewOfFile, FormatMessageA, LocalFree, GetCurrentDirectoryA, SetVolumeLabelA, GetDiskFreeSpaceA, GetDriveTypeA, CreateDirectoryA, MoveFileA, DeleteFileA, GetFileSize, lstrlenA, CompareStringW, CompareStringA, GetVersion, GetLastError, MultiByteToWideChar, InterlockedExchange, GetDiskFreeSpaceExA, GetFileAttributesA, SetFileAttributesA, GetModuleFileNameA, WideCharToMultiByte, FindResourceA, LoadResource, LockResource, SizeofResource, CreateFileA, SetFilePointer, WriteFile, SetUnhandledExceptionFilter, CloseHandle
> USER32.dll: GetSysColorBrush, ShowWindow, RegisterWindowMessageA, LoadIconA, WinHelpA, GetCapture, GetClassLongA, SetPropA, GetPropA, RemovePropA, IsWindow, GetForegroundWindow, GetDlgItem, GetTopWindow, DestroyWindow, GetMessageTime, GetMessagePos, MapWindowPoints, SetForegroundWindow, GetClientRect, GetMenu, CreateWindowExA, GetClassInfoExA, GetClassInfoA, AdjustWindowRectEx, CopyRect, DefWindowProcA, CallWindowProcA, SetWindowLongA, SetWindowPos, SystemParametersInfoA, IsIconic, GetWindow, GetDlgCtrlID, GetWindowRect, GetClassNameA, PtInRect, GetWindowTextA, SetWindowTextA, GetSysColor, ReleaseDC, GetDC, ClientToScreen, GrayStringA, DrawTextExA, DrawTextA, TabbedTextOutA, wsprintfA, CharUpperA, UnregisterClassA, GetSystemMetrics, UnhookWindowsHookEx, GetMenuItemID, GetMenuItemCount, GetSubMenu, GetWindowThreadProcessId, DestroyMenu, RegisterClassA, LoadCursorA, OemToCharBuffA, CharToOemBuffA, PostQuitMessage, PostMessageA, CheckMenuItem, EnableMenuItem, GetMenuState, ModifyMenuA, SendMessageA, GetParent, GetFocus, LoadBitmapA, GetMenuCheckMarkDimensions, SetMenuItemBitmaps, ValidateRect, GetCursorPos, PeekMessageA, GetWindowLongA, GetLastActivePopup, IsWindowEnabled, EnableWindow, MessageBoxA, SetCursor, SetWindowsHookExA, CallNextHookEx, GetMessageA, TranslateMessage, DispatchMessageA, GetActiveWindow, IsWindowVisible, GetKeyState, GetWindowPlacement
> GDI32.dll: DeleteDC, GetStockObject, SetWindowExtEx, ScaleWindowExtEx, ScaleViewportExtEx, SetViewportExtEx, OffsetViewportOrgEx, SetViewportOrgEx, SelectObject, Escape, ExtTextOutA, TextOutA, RectVisible, CreateBitmap, DeleteObject, GetClipBox, SetMapMode, SetTextColor, SetBkColor, RestoreDC, SaveDC, GetDeviceCaps, PtVisible
> COMDLG32.dll: GetFileTitleA
> WINSPOOL.DRV: DocumentPropertiesA, OpenPrinterA, ClosePrinter
> ADVAPI32.dll: RegSetValueExA, RegCreateKeyExA, RegQueryValueA, RegOpenKeyA, RegEnumKeyA, RegDeleteKeyA, RegOpenKeyExA, RegQueryValueExA, RegCloseKey
> SHLWAPI.dll: PathFindExtensionA, PathFindFileNameA, PathStripToRootA, PathIsUNCA
> OLEAUT32.dll: -, -, -

( 3 exports )
DecodeCapsule, DoCapsule, unZipFile
RDS…: NSRL Reference Data Set
- pdfid.: - sigcheck:
publisher….: Wistron Corp.
copyright….: Copyright © 2003-2008
product……: Capsule Dynamic Link Library
description..: Capsule DLL
original name: n/a
internal name: Capsule
file version.: 1, 0, 1, 1
comments…..: n/a
signers……: Wistron Corporation
VeriSign Class 3 Code Signing 2004 CA
Class 3 Public Primary Certification Authority
signing date.: 3:49 PM 10/20/2009
verified…..: -
trid..: Win32 Executable MS Visual C++ (generic) (65.2%)
Win32 Executable Generic (14.7%)
Win32 Dynamic Link Library (generic) (13.1%)
Generic Win/DOS Executable (3.4%)
DOS Executable Generic (3.4%) My computer is acting fine at the moment.
Hi,

Am not seeing any malware. Let's do a couple more scans to be sure.

Please download Malwarebytes' Anti-Malware to your desktop.
  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
    [external image: Posted Image]
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected.
  • When completed, a log will open in Notepad. Please save it to a convenient location and post back the log.
Extra Note:
If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer, please do so immediately.

–Next–


Please do a scan with Kaspersky Online Scanner.
  • Click on the Accept button and install any components it needs.
  • The program will install and then begin downloading the latest definition files.
  • After the files have been downloaded on the left side of the page in the Scan section select My Computer.
  • This will start the program and scan your system.
  • The scan will take a while, so be patient and let it run. (At times it may appear to stall)
  • Once the update is complete, click on My Computer under the green Scan bar to the left to start the scan.
    • Once the scan is complete, it will display if your system has been infected. It does not provide an option to clean/disinfect. We only require a report from it.
    • Do NOT be alarmed by what you see in the report. Many of the finds have likely been quarantined.
  • Once the scan is complete, click on View scan report To obtain the report:
  • Click on: Save Report As
  • Next, in the Save as prompt, Save in area, select: Desktop
  • In the File name area, use KScan, or something similar In Save as type, click the drop arrow and select: Text file [*.txt]
  • Then, click: Save
  • Please post the Kaspersky Online Scanner Report in your reply.
To post in your next reply:
1. Malwarebytes' log.
2. Kaspersky log.
Malwarebytes' Anti-Malware 1.44 Database version: 3600 Windows 6.1.7600 Internet Explorer 8.0.7600.16385 1/19/2010 5:42:45 PM mbam-log-2010-01-19 (17-42-45).txt Scan type: Quick Scan Objects scanned: 94559 Time elapsed: 1 minute(s), 15 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected) ——————————————————————————– KASPERSKY ONLINE SCANNER 7.0: scan report Wednesday, January 20, 2010 Operating system: Microsoft (build 7600) Kaspersky Online Scanner version: 7.0.26.13 Last database update: Wednesday, January 20, 2010 22:37:18 Records in database: 3350959 ——————————————————————————– Scan settings: scan using the following database: extended Scan archives: yes Scan e-mail databases: yes Scan area - My Computer: C:\ D:\ Scan statistics: Objects scanned: 158295 Threats found: 0 Infected objects found: 0 Suspicious objects found: 0 Scan duration: 02:02:32 No threats found. Scanned area is clean. Selected area has been scanned.
Hi,

Your computer appears to be clean.

Let's do some clean up before you go.

Please delete, DDS, GMER, Rooter and all the logs we've created.

–Next–

You can keep Malwarebytes, it is an excellent malware removal tool. Update atleast once a week then run a complete scan.

–Next–

You need to create a new Clean restore point.
  • Click Start - All Programs - Accessories - System Tools - System Restore
  • Click on open System Protection.
  • On the System Protection tab in System Properties click on Create.
  • Give the restore point an appropriate name and click Create.
Remove all previous Restore Points
Click Start Menu > Run > copy and paste
  • Open any folder.
  • Click on Organize button.
  • Select Folders and Search Options.
  • On the Folder Options window, click on View tab.
  • Select Show hidden files and folders from the list.
  • Click OK to save the new settings and close the Folder Options window.
–Next–

To keep your operating system up to date visit
  • Secunia Software inspector to check your program update status.
  • Microsoft Windows Update .

Here are some tips to reduce the potential for spyware infection in the future:

1. Make your Internet Explorer More Secure
  • From within Internet Explorer click on the Tools menu and then click on Options.
  • Click once on the Security tab.
  • Click once on the Internet icon so it becomes highlighted.
  • Click once on the Custom Level button.

    • Change the Download signed ActiveX controls to Prompt.
    • Change the Download unsigned ActiveX controls to Disable.
    • Change the Initialise and script ActiveX controls not marked as safe to Disable.
    • Change the Installation of desktop items to Prompt.
    • Change the Launching programs and files in an IFRAME to Prompt.
    • Change the Navigate sub-frames across different domains to Prompt.
    • When all these settings have been made, click on the OK button.
    • If it prompts you as to whether or not you want to save the settings, press the Yes button.
  • Next press the Apply button and then the OK to exit the Internet Properties page.
2. Update your Anti-Virus Software - I can not overemphasize the need for you to update your Anti-virus application on a regular basis. With the ever increasing number of new variants of malware arriving on the scene daily, you become very susceptible to an attack without updated protection.

3. Make sure you keep your Windows OS current by visiting Windows update regularly to download and install any critical updates and service packs. Without these you are leaving the back door open.

4. Consider a custom hosts file such as MVPS HOSTS. This custom hosts file effectively blocks a wide range of unwanted ads, banners, 3rd party Cookies, 3rd party page counters, web bugs, and many hijackers.
For information on how to download and install, please read this tutorial by WinHelp2002
Note: Be sure to follow the instructions to disable the DNS Client service before installing a custom hosts file.

5. Download and install the free version of WinPatrol. This program protects your computer in a variety of ways and will work well with your existing security software. Have a look at this tutorial to help you get started with the program.

6. SpywareBlaster - Download and install SpywareBlaster. This program prevents the installation of ActiveX-based spyware and other potentially unwanted programs.

7. Protect your computer from internet threats with SandboxIE. This program isolates Internet Explorer from the rest of your operating system, 'sandboxing' it away - so malicious websites can't do damage to the rest of your system. There is a Getting Started guide on their website.

8. Some excellent free firewalls. Note: Use only one firewall at a time.
Agnitum Outpost Firewall
Comodo Firewall - If you are installing this and already have an anti spyware then please do not install Comodo's anti spyware program.
Online Armor Personal Firewall

9. And finally, please read these excellent articles:
Malware: Help prevent the Infection by Sandi Hardmeier,
Preventing Malware - Tools and Practices for Safe Computing

For more safe computing tips please read the guide by Rorschach112 on how to prevent malware and about safe computing here.



Goodluck, happy computing and stay clean! ^_^
Since this issue appears to be resolved … this Topic has been closed. Glad we could be of assistance. If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread. Everyone else please begin a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI