This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Worm.Win32.Netsky ?

21 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

A couple of days ago my old XP desktop started to show some random popups. Today that switched to something more sinister as the screen has changed to a bright color of green and a large message of System Infected is remaining on the screen. I can't seem to do anything with the computer and am typing this from a second computer in the house. Every time we reboot it just comes back to the same green screen and we can't do any more with it from there. There was one note referencing this on one of the screens Worm.Win32.Netsky Thank you
Hi maldini,

Is this the same computer that we cleaned before?


Go HERE to download GMER. Scroll down to the Download section and click Download EXE. Save it to your desktop.

Before scanning with GMER, make sure all other running programs are closed and no other actions like a scheduled antivirus scan will occur while the scan is being performed. Do not use your computer for anything else during the scan.

  • Double click on the file you downloaded. If asked to allow gmer.sys driver to load, please consent .
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.

    [external image: Posted Image]
    Click the image to enlarge it
  • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • Sections
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and post it in your next reply.

**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries




Download OTL to your desktop.
  • Double click on OTL.exe to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output
  • Check the boxes beside LOP Check and Purity Check.
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.

Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply. You may need two posts to fit them all in.

Please post back with
  • GMER logs
  • both OTL logs

Thanks
Hi Oldman, This is a different computer. The one you fixed was my netbook and is working great. The infected computer is an old desktop. I can not do anything on that desktop. I can not launch any applications, including Firefox or IE to get to GMER or OTL. No matter what I click on, it does not launch. Just popup city and the hard drive cranking away like it is on speed. Is there a way I should start the computer in some sort of safe mode so that I can get online to get to the tools?
oh good news! After about 90 minutes I was able to download GMER and it is scanning now. Hopefully I can get to OTL as well and then post both logs. Not pretty :)
Hi Oldman, I am having a very hard time. I am posting from a different computer. GMER did finish and I do have a log file. OTL ran once for 2 hours, sand got stuck with an error pop up window stating that a certain date was not valid. I ran OTL again over night but it hung in the exact same place. I have been trying to post the GMER log but it is extremely difficult to get to the forums and log on because the computer does not let me do much. Everything is extraordinarily slow, firefox or IE hangs or the system reboots itself. I will try again now to see if I can make it to the point where I can post at least the GMER log for you.
GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-01-29 20:40:32
Windows 5.1.2600 Service Pack 2
Running: g6kehkqq.exe; Driver: C:\DOCUME~1\Owner\LOCALS~1\Temp\pwldrpob.sys


—- Devices - GMER 1.0.15 —-

AttachedDevice \FileSystem\Ntfs \Ntfs SYMEVENT.SYS (Symantec Event Library/Symantec Corporation)
AttachedDevice \Driver\Tcpip \Device\Ip SYMTDI.SYS (Norton Internet Security Filter/Symantec Corporation)
AttachedDevice \Driver\Tcpip \Device\Tcp SYMTDI.SYS (Norton Internet Security Filter/Symantec Corporation)
AttachedDevice \Driver\Tcpip \Device\Udp SYMTDI.SYS (Norton Internet Security Filter/Symantec Corporation)
AttachedDevice \Driver\Tcpip \Device\RawIp SYMTDI.SYS (Norton Internet Security Filter/Symantec Corporation)
AttachedDevice \FileSystem\Fastfat \Fat SYMEVENT.SYS (Symantec Event Library/Symantec Corporation)

Device -> \Driver\atapi \Device\Harddisk0\DR0 81286856

—- Registry - GMER 1.0.15 —-

Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\run@nesurukeb Rundll32.exe "c:\windows\system32\jilumuyo.dll",a
Reg HKLM\SOFTWARE\Classes\CLSID\{dc248c7b-e593-4c32-a231-b58c2eb89e12}\InprocServer32@ c:\windows\system32\fodelaki.dll

—- Files - GMER 1.0.15 —-

File C:\Documents and Settings\Owner\Cookies\owner@go[10].txt 0 bytes
File C:\WINDOWS\system32\drivers\atapi.sys suspicious modification

—- EOF - GMER 1.0.15 —-
Hi malidii,

Don't worry about OTL for now, GMER has shown use enough to prceed.


Please read through the instructions to familarize youself with what to expect when the tool runs.

It is vitally important that combofix is renamed before it is even started to download


Please download ComboFix from Link 1or Link 2 to your Desktop.

**Note: In the event you already have Combofix, this is a new version that I need you to download. It is important that it is saved directly to your desktop**

  • If you are using Firefox, make sure that your download settings are as follows:
    -Tools->Options->Main tab
    -Set to "Always ask me where to Save the files".
  • During the download, before you save it to your desktop, rename Combofix to jgh.exe

  • It is important you rename Combofix during the download, but not after.
  • Please do not rename Combofix to other names, but only to the one indicated.
  • Close any open browsers.
  • Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix

———————————————————–

  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before performing a scan. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
  • Click on this link to see a list of programs that should be disabled. The list is not all inclusive. If yours is not listed and you don't know how to disable it, please ask.

    ———————————————————–

  • Double click on ComboFix.exe (jgh.exe in your case) & follow the prompts.
  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]


Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]

Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.

Notes:

1.Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
3. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.

Please post back with
  • combofix log
How is the computer?

Thanks
computer is back to normal now! whew. No pop ups, nothing running in the back ground, and speed is back to where it was. Thank you!!!

ComboFix 10-01-29.09 - Owner 2010-01-30 10:32:19.3.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.247.60 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\jgh.exe
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\Owner\Application Data\Microsoft\Internet Explorer\Quick Launch\Internet Security 2010.lnk
c:\documents and settings\Owner\Desktop\Internet Security 2010.lnk
c:\documents and settings\Owner\Start Menu\Internet Security 2010.lnk
c:\program files\InternetSecurity2010
c:\program files\InternetSecurity2010\IS2010.exe
c:\windows\system32\15724.exe
c:\windows\system32\18467.exe
c:\windows\system32\19169.exe
c:\windows\system32\26500.exe
c:\windows\system32\41.exe
c:\windows\system32\6334.exe
c:\windows\system32\a.exe
c:\windows\system32\hapoyivu.dll
c:\windows\system32\helper32.dll
c:\windows\system32\hujinuya.dll
c:\windows\system32\iAlmcoin.dll
c:\windows\system32\jayodaye.dll
c:\windows\system32\kifabibu.dll
c:\windows\system32\noveyobe.dll
c:\windows\system32\ps2.bat
c:\windows\system32\smss32.exe
c:\windows\system32\warning.html
c:\windows\system32\wezahevu.dll
c:\windows\system32\winlogon32.exe
c:\windows\system32\yireniye.dll
c:\windows\system32\yojonaso.dll
c:\windows\system32\yuheduwo.dll
c:\windows\system32\zowolage.dll
c:\windows\Tasks\anryxovq.job
c:\windows\unins000.dat
c:\windows\unins000.exe

Infected copy of c:\windows\system32\DRIVERS\atapi.sys was found and disinfected
Restored copy from - Kitty ate it :P
.
((((((((((((((((((((((((( Files Created from 2009-12-28 to 2010-01-30 )))))))))))))))))))))))))))))))
.

No new files created in this timespan

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-01-30 15:49 . 2003-12-30 23:50 ——– d—–w- c:\documents and settings\All Users\Application Data\DIGStream
2010-01-30 15:49 . 2003-08-29 03:15 ——– d—–w- c:\program files\Common Files\Symantec Shared
2010-01-27 19:40 . 2006-06-29 17:02 ——– d—–w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2010-01-27 00:58 . 2006-06-29 17:02 ——– d—–w- c:\program files\Spybot - Search & Destroy
2010-01-26 23:41 . 2006-12-23 20:11 ——– d—a-w- c:\documents and settings\All Users\Application Data\TEMP
2010-01-10 22:56 . 2003-12-24 16:58 ——– d—–w- c:\documents and settings\Owner\Application Data\AdobeUM
2009-12-21 19:14 . 2005-02-18 20:19 916480 —-a-w- c:\windows\system32\wininet.dll
2008-06-19 09:16 . 2008-06-19 09:16 118784 —-a-w- c:\program files\mozilla firefox\plugins\MyCamera.dll
2003-08-29 03:16 . 2003-08-29 03:16 32 –sha-w- c:\windows\{14B431FF-99E9-4C1E-8574-051F227CB5BD}.dat
1601-01-01 00:03 . 1601-01-01 00:03 52736 –sha-w- c:\windows\system32\bidubiti.dll.tmp
1601-01-01 00:03 . 1601-01-01 00:03 39424 –sha-w- c:\windows\system32\fizelugo.dll
1601-01-01 00:03 . 1601-01-01 00:03 51712 –sha-w- c:\windows\system32\hajulofi.dll
1601-01-01 00:03 . 1601-01-01 00:03 92160 –sha-w- c:\windows\system32\hulujige.dll
1601-01-01 00:03 . 1601-01-01 00:03 52736 –sha-w- c:\windows\system32\jimaneno.dll.tmp
1601-01-01 00:03 . 1601-01-01 00:03 52736 –sha-w- c:\windows\system32\lumekeri.dll.tmp
1601-01-01 00:03 . 1601-01-01 00:03 93696 –sha-w- c:\windows\system32\nifarake.dll
1601-01-01 00:03 . 1601-01-01 00:03 61952 –sha-w- c:\windows\system32\rolirefu.dll
1601-01-01 00:03 . 1601-01-01 00:03 39424 –sha-w- c:\windows\system32\suzirowa.dll
1601-01-01 00:03 . 1601-01-01 00:03 51712 –sha-w- c:\windows\system32\vozanije.dll
2003-08-29 03:16 . 2003-08-29 03:16 32 –sha-w- c:\windows\system32\{C6B785D4-A2EC-4320-AADD-7778E174E81D}.dat
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{c0fe0be6-08ae-4b27-bb91-ba35694c0375}]
1601-01-01 00:03 51712 –sha-w- c:\windows\system32\vozanije.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BackupNotify"="c:\program files\Hewlett-Packard\Digital Imaging\bin\backupnotify.exe" [2003-06-23 24576]
"NVIEW"="nview.dll" [2003-05-03 835654]
"PopUpStopperFreeEdition"="c:\progra~1\PANICW~1\POP-UP~1\PSFree.exe" [2003-10-29 524288]
"RealPlayer"="c:\program files\Real\RealOne Player\realplay.exe" [2006-06-01 1003520]
"PhotoShow Deluxe Media Manager"="c:\progra~1\WALGRE~1\WALGRE~1\data\Xtras\mssysmgr.exe" [2005-05-19 176128]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-01-26 2144088]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"HotKeysCmds"="c:\windows\System32\hkcmd.exe" [2004-08-20 118784]
"hpsysdrv"="c:\windows\system\hpsysdrv.exe" [1998-05-07 52736]
"CamMonitor"="c:\program files\Hewlett-Packard\Digital Imaging\\Unload\hpqcmon.exe" [2002-10-07 90112]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd.exe" [2003-06-14 49152]
"HPHUPD05"="c:\program files\Hewlett-Packard\{45B6180B-DCAB-4093-8EE8-6164457517F0}\hphupd05.exe" [2003-05-23 49152]
"HPHmon05"="c:\windows\System32\hphmon05.exe" [2003-05-23 483328]
"KBD"="c:\hp\KBD\KBD.EXE" [2003-02-12 61440]
"StorageGuard"="c:\program files\Common Files\Sonic\Update Manager\sgtray.exe" [2003-02-13 155648]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2003-08-23 151597]
"Recguard"="c:\windows\SMINST\RECGUARD.EXE" [2002-09-14 212992]
"NvCplDaemon"="c:\windows\System32\NvCpl.dll" [2003-05-03 4640768]
"nwiz"="nwiz.exe" [2003-05-03 323584]
"ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2003-12-02 54296]
"ccRegVfy"="c:\program files\Common Files\Symantec Shared\ccRegVfy.exe" [2003-12-02 58392]
"PS2"="c:\windows\system32\ps2.exe" [2002-10-16 81920]
"HPDJ Taskbar Utility"="c:\windows\System32\spool\drivers\w32x86\3\hpztsb05.exe" [2002-03-18 188416]
"DIGStream"="c:\program files\DIGStream\digstream.exe" [2005-05-18 282624]
"Microsoft Works Update Detection"="c:\program files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe" [2002-07-17 28672]
"IgfxTray"="c:\windows\System32\igfxtray.exe" [2004-08-20 155648]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2005-12-21 278528]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2006-01-21 155648]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Configuration Utility.lnk - c:\program files\MA311 PCI Adapter Configuration Utility\wlanutil.exe [2003-12-12 625152]
Event Reminder.lnk - c:\program files\Broderbund\PrintMaster\PMremind.exe [2008-9-13 331776]
HP Digital Imaging Monitor.lnk - c:\program files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe [2003-6-13 233472]
Updates from HP.lnk - c:\program files\Updates from HP\137903\Program\BackWeb-137903.exe [2003-8-23 16384]
WinZip Quick Pick.lnk - c:\program files\WinZip\WZQKPICK.EXE [2006-1-28 122880]

[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoSetActiveDesktop"= 1 (0x1)
"NoActiveDesktopChanges"= 1 (0x1)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\OPXPGina]
2003-02-21 10:50 40960 —-a-w- c:\program files\Softex\OmniPass\OPXPGina.dll

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Notification Packages REG_MULTI_SZ scecli pnfligi.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]
@="Service"

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Updates from HP\\137903\\Program\\BackWeb-137903.exe"=
"c:\\Program Files\\Hummingbird\\Connectivity\\8.00\\Exceed\\exceed.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"c:\\Documents and Settings\\Owner\\My Documents\\PCDnldSvr\\PCDnldServer.exe"=

R3 MA311;NETGEAR Wireless LAN Driver;c:\windows\system32\drivers\ma311n51.sys [2003-12-12 7:08 PM 54784]
S2 mrtRate;mrtRate; [x]
S3 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [2007-11-06 3:22 PM 34064]
.
Contents of the 'Scheduled Tasks' folder

2010-01-30 c:\windows\Tasks\Norton AntiVirus - Scan my computer.job
- c:\progra~1\NORTON~1\NAVW32.exe [2002-11-15 09:31]

2004-01-09 c:\windows\Tasks\Symantec NetDetect.job
- c:\program files\Symantec\LiveUpdate\NDETECT.EXE [2003-08-29 19:20]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.yahoo.com/
uDefault_Search_URL = hxxp://srch-us9.hpwis.com/
mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride = localhost
uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ie/defaults/su/msgr8/*http://www.yahoo.com
IE: &Google; Search - c:\program files\google\GoogleToolbar2.dll/cmsearch.html
IE: &Translate; English Word - c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html
IE: &Yahoo;! Search - file:///c:\program files\Yahoo!\Common/ycsrch.htm
IE: Backward Links - c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
IE: Cached Snapshot of Page - c:\program files\google\GoogleToolbar2.dll/cmcache.html
IE: Similar Pages - c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
IE: Translate Page into English - c:\program files\google\GoogleToolbar2.dll/cmtrans.html
IE: Yahoo! &Dictionary; - file:///c:\program files\Yahoo!\Common/ycdict.htm
IE: Yahoo! &Maps; - file:///c:\program files\Yahoo!\Common/ycmap.htm
IE: Yahoo! &SMS; - file:///c:\program files\Yahoo!\Common/ycsms.htm
LSP: SpSubLSP.dll
Trusted Zone: turbotax.com
DPF: DirectAnimation Java Classes - file://c:\windows\Java\classes\dajava.cab
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
FF - ProfilePath - c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\etmra113.default\
FF - prefs.js: browser.startup.homepage - www.google.com
FF - plugin: c:\progra~1\Yahoo!\Common\npyaxmpb.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\NPCIG.dll
FF - plugin: c:\program files\Real\RealOne Player\Netscape6\nppl3260.dll
FF - plugin: c:\program files\Real\RealOne Player\Netscape6\nprjplug.dll
FF - plugin: c:\program files\Real\RealOne Player\Netscape6\nprpjplug.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
.
- - - - ORPHANS REMOVED - - - -

HKLM-Run-derirowaki - wezahevu.dll
HKLM-Run-nesurukeb - c:\windows\system32\hapoyivu.dll
SharedTaskScheduler-{f0c266d6-ee2e-47dd-8cfa-22132e89416f} - c:\windows\system32\jilumuyo.dll
SharedTaskScheduler-{76a2b722-7c62-4fdc-8007-6e49c465ce2b} - c:\windows\system32\hapoyivu.dll
SSODL-neletedos-{f0c266d6-ee2e-47dd-8cfa-22132e89416f} - c:\windows\system32\jilumuyo.dll
SSODL-genojomid-{76a2b722-7c62-4fdc-8007-6e49c465ce2b} - c:\windows\system32\hapoyivu.dll
AddRemove-1ABC286C-DE10-4590-BEFF-4D0DFF5EA1EC - c:\program files\WildTangent\Apps\GameChannel\Games\1ABC286C-DE10-4590-BEFF-4D0DFF5EA1EC\Uninstall.exe
AddRemove-1FEF9671-50F6-4CB0-9E96-304EB14158E0 - c:\program files\WildTangent\Apps\GameChannel\Games\1FEF9671-50F6-4CB0-9E96-304EB14158E0\Uninstall.exe
AddRemove-342970EF-F8DF-4E9B-8477-A1A03E3E15E1 - c:\program files\WildTangent\Apps\GameChannel\Games\342970EF-F8DF-4E9B-8477-A1A03E3E15E1\Uninstall.exe
AddRemove-357ECB62-CD36-4B63-B57E-769D0CA174F4 - c:\program files\WildTangent\Apps\GameChannel\Games\357ECB62-CD36-4B63-B57E-769D0CA174F4\Uninstall.exe
AddRemove-36317AE4-57EC-4F3E-B828-009A3DD96BE8 - c:\program files\WildTangent\Apps\GameChannel\Games\36317AE4-57EC-4F3E-B828-009A3DD96BE8\Uninstall.exe
AddRemove-4F0AE1FB-4082-4A27-8363-05D292D92FB0 - c:\program files\WildTangent\Apps\GameChannel\Games\4F0AE1FB-4082-4A27-8363-05D292D92FB0\Uninstall.exe
AddRemove-53EF27E9-150C-4063-8343-61C45FC6BB98 - c:\program files\WildTangent\Apps\GameChannel\Games\53EF27E9-150C-4063-8343-61C45FC6BB98\Uninstall.exe
AddRemove-5415BC25-6D6C-46C4-B34C-EA8470FE56D5 - c:\program files\WildTangent\Apps\GameChannel\Games\5415BC25-6D6C-46C4-B34C-EA8470FE56D5\Uninstall.exe
AddRemove-5F804D2B-A66D-4F0A-B64E-FBDA3F52E3F8 - c:\program files\WildTangent\Apps\GameChannel\Games\5F804D2B-A66D-4F0A-B64E-FBDA3F52E3F8\Uninstall.exe
AddRemove-62067F4C-84A9-45B9-8573-B90468B0A3EF - c:\program files\WildTangent\Apps\GameChannel\Games\62067F4C-84A9-45B9-8573-B90468B0A3EF\Uninstall.exe
AddRemove-BFBCBAE3-8293-4215-9C4F-C2402C118EDB - c:\program files\WildTangent\Apps\GameChannel\Games\BFBCBAE3-8293-4215-9C4F-C2402C118EDB\Uninstall.exe
AddRemove-C99127BE-FDE5-49BD-9621-BFE5DF19AA34 - c:\program files\WildTangent\Apps\GameChannel\Games\C99127BE-FDE5-49BD-9621-BFE5DF19AA34\Uninstall.exe
AddRemove-D11F7128-8CBD-408B-8BF8-034604DEDD42 - c:\program files\WildTangent\Apps\GameChannel\Games\D11F7128-8CBD-408B-8BF8-034604DEDD42\Uninstall.exe
AddRemove-DA44615A-C243-46A4-8E47-184CFF33CD38 - c:\program files\WildTangent\Apps\GameChannel\Games\DA44615A-C243-46A4-8E47-184CFF33CD38\Uninstall.exe
AddRemove-DF479CEA-34C0-460F-9B56-93BCE4CD4086 - c:\program files\WildTangent\Apps\GameChannel\Games\DF479CEA-34C0-460F-9B56-93BCE4CD4086\Uninstall.exe
AddRemove-GameChannel - c:\program files\WildTangent\Apps\uninstallgamechannel.exe
AddRemove-Spybot - Search & Destroy_is1 - c:\windows\unins000.exe



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-01-30 10:47
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(592)
c:\program files\Softex\OmniPass\opxpgina.dll

- - - - - - - > 'lsass.exe'(648)
c:\windows\pnfligi.dll
c:\windows\system32\WININET.dll
c:\windows\system32\SpSubLSP.dll

- - - - - - - > 'explorer.exe'(2832)
c:\windows\system32\WININET.dll
c:\docume~1\Owner\LOCALS~1\Temp\IadHide4.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\mshtml.dll
c:\windows\system32\msls31.dll
c:\windows\pnfligi.dll
c:\windows\system32\webcheck.dll
c:\progra~1\PANICW~1\POP-UP~1\XAHook.dll
.
———————— Other Running Processes ————————
.
c:\program files\Lavasoft\Ad-Aware\aawservice.exe
c:\program files\Common Files\Symantec Shared\ccEvtMgr.exe
c:\program files\Common Files\Intuit\Update Service\IntuitUpdateService.exe
c:\program files\Norton AntiVirus\navapsvc.exe
c:\program files\Softex\OmniPass\Omniserv.exe
c:\program files\Canon\CAL\CALMAIN.exe
c:\program files\Softex\OmniPass\OPXPApp.exe
c:\windows\system32\wscntfy.exe
c:\program files\Hewlett-Packard\Digital Imaging\Unload\hpqcmon.exe
c:\program files\Common Files\Real\Update_OB\rnathchk.exe
c:\program files\iPod\bin\iPodService.exe
c:\progra~1\Yahoo!\MESSEN~1\ymsgr_tray.exe
c:\program files\Java\jre1.6.0_07\bin\jucheck.exe
c:\windows\system32\rundll32.exe
c:\program files\Messenger\msmsgs.exe
.
**************************************************************************
.
Completion time: 2010-01-30 11:16:21 - machine was rebooted
ComboFix-quarantined-files.txt 2010-01-30 16:16
ComboFix2.txt 2008-09-03 23:34

Pre-Run: 50,301,153,280 bytes free
Post-Run: 50,355,994,624 bytes free

- - End Of File - - F2211A04B543B3B3293F8B687A8000A2
Hi maldini,

This computer doesn't have and antivirus program installed. I'll give you some links to a free one afterwards. It does look like Norton (Symantec) was installed at one time.

We will use combofix again but run it differently.

Please follow all previous instructions regarding security programs.

Open a new Notepad session
  • Click the Start button, click run
  • in the run box type notepad
  • click ok
  • In the notepad, Click "Format" and be certain that Word Wrap is not checked.
  • Copy and paste all the text in the code box below into the Notepad. Do Not copy the word CODE

File::
c:\windows\system32\bidubiti.dll.tmp
c:\windows\system32\fizelugo.dll
c:\windows\system32\hajulofi.dll
c:\windows\system32\hulujige.dll
c:\windows\system32\jimaneno.dll.tmp
c:\windows\system32\lumekeri.dll.tmp
c:\windows\system32\nifarake.dll
c:\windows\system32\rolirefu.dll
c:\windows\system32\suzirowa.dll
c:\windows\system32\vozanije.dll
c:\windows\pnfligi.dll

Registry::
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
"Notification Packages"=hex(7):73,63,65,63,6c,69,00,00
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{c0fe0be6-08ae-4b27-bb91-ba35694c0375}]

driver::
mrtRate

In the notepad
  • Click File, Save as…, and set the Save in to your Desktop
  • In the filename box, type (including quotation marks) as the filename: "CFScript.txt"
  • Click save
Using your mouse left button, drag the new file CFscript.txt and drop it on the ComboFix.exe icon as shown below.

This will start ComboFix again.Close all browser/windows first.

**Note: Do not mouseclick combofix's window while it's running. That may cause it to stall**

[external image: Posted Image]




Download and save to your desktop Malwarebytes Anti-Malware

Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.
Extra Note:
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediatly.


Please post back with the
  • combofix log
  • MBAM log
Thanks
ComboFix 10-01-29.09 - Owner 2010-01-30 20:37:46.5.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.247.77 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\jgh.exe
Command switches used :: c:\documents and settings\Owner\Desktop\CFScript.txt

FILE ::
"c:\windows\pnfligi.dll"
"c:\windows\system32\bidubiti.dll.tmp"
"c:\windows\system32\fizelugo.dll"
"c:\windows\system32\hajulofi.dll"
"c:\windows\system32\hulujige.dll"
"c:\windows\system32\jimaneno.dll.tmp"
"c:\windows\system32\lumekeri.dll.tmp"
"c:\windows\system32\nifarake.dll"
"c:\windows\system32\rolirefu.dll"
"c:\windows\system32\suzirowa.dll"
"c:\windows\system32\vozanije.dll"
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\pnfligi.dll

.
((((((((((((((((((((((((( Files Created from 2009-12-28 to 2010-01-31 )))))))))))))))))))))))))))))))
.

2010-01-28 13:22 . 2010-01-28 13:22 ——– d-sh–w- c:\windows\system32\config\systemprofile\IETldCache
2010-01-27 15:39 . 2010-01-27 15:39 ——– d-sh–w- c:\documents and settings\Owner\IECompatCache

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-01-31 01:51 . 2003-12-30 23:50 ——– d—–w- c:\documents and settings\All Users\Application Data\DIGStream
2010-01-30 17:35 . 2003-08-23 14:12 85320 —-a-w- c:\documents and settings\Owner\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-01-30 17:21 . 2006-06-29 17:02 ——– d—–w- c:\program files\Spybot - Search & Destroy
2010-01-30 17:21 . 2006-06-29 17:02 ——– d—–w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2010-01-30 17:20 . 2003-08-23 14:19 ——– d–h–w- c:\program files\InstallShield Installation Information
2010-01-30 17:20 . 2004-01-02 20:11 ——– d—–w- c:\program files\Scholastic
2010-01-30 17:19 . 2004-02-10 21:06 ——– d—–w- c:\program files\The Learning Company
2010-01-30 17:18 . 2003-08-29 03:16 ——– d—–w- c:\documents and settings\All Users\Application Data\Symantec
2010-01-30 17:18 . 2003-08-29 03:15 ——– d—–w- c:\program files\Norton AntiVirus
2010-01-30 17:18 . 2003-08-29 03:15 ——– d—–w- c:\program files\Common Files\Symantec Shared
2010-01-30 17:17 . 2003-08-29 03:15 ——– d—–w- c:\program files\Symantec
2010-01-30 17:14 . 2003-08-23 14:19 ——– d—–w- c:\program files\Common Files\InstallShield
2010-01-30 17:11 . 2006-12-23 18:48 ——– d—–w- c:\program files\Comcast Play Games
2010-01-30 17:07 . 2004-07-13 20:01 ——– d—–w- c:\program files\Barbie™
2010-01-30 17:06 . 2008-06-28 17:32 ——– d—–w- c:\program files\Common Files\Wise Installation Wizard
2010-01-30 17:05 . 2006-06-29 17:03 ——– d—–w- c:\program files\Lavasoft
2010-01-26 23:41 . 2006-12-23 20:11 ——– d—a-w- c:\documents and settings\All Users\Application Data\TEMP
2010-01-10 22:56 . 2003-12-24 16:58 ——– d—–w- c:\documents and settings\Owner\Application Data\AdobeUM
2009-12-21 19:14 . 2005-02-18 20:19 916480 ——w- c:\windows\system32\wininet.dll
2009-11-21 16:36 . 2003-08-25 21:25 470528 —-a-w- c:\windows\AppPatch\aclayers.dll
2008-06-19 09:16 . 2008-06-19 09:16 118784 —-a-w- c:\program files\mozilla firefox\plugins\MyCamera.dll
1601-01-01 00:03 . 1601-01-01 00:03 61440 –sha-w- c:\windows\system32\fipuyuko.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BackupNotify"="c:\program files\Hewlett-Packard\Digital Imaging\bin\backupnotify.exe" [2003-06-23 24576]
"NVIEW"="nview.dll" [2003-05-03 835654]
"PopUpStopperFreeEdition"="c:\progra~1\PANICW~1\POP-UP~1\PSFree.exe" [2003-10-29 524288]
"RealPlayer"="c:\program files\Real\RealOne Player\realplay.exe" [2006-06-01 1003520]
"PhotoShow Deluxe Media Manager"="c:\progra~1\WALGRE~1\WALGRE~1\data\Xtras\mssysmgr.exe" [2005-05-19 176128]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"HotKeysCmds"="c:\windows\System32\hkcmd.exe" [2004-08-20 118784]
"hpsysdrv"="c:\windows\system\hpsysdrv.exe" [1998-05-07 52736]
"CamMonitor"="c:\program files\Hewlett-Packard\Digital Imaging\\Unload\hpqcmon.exe" [2002-10-07 90112]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd.exe" [2003-06-14 49152]
"HPHUPD05"="c:\program files\Hewlett-Packard\{45B6180B-DCAB-4093-8EE8-6164457517F0}\hphupd05.exe" [2003-05-23 49152]
"HPHmon05"="c:\windows\System32\hphmon05.exe" [2003-05-23 483328]
"KBD"="c:\hp\KBD\KBD.EXE" [2003-02-12 61440]
"StorageGuard"="c:\program files\Common Files\Sonic\Update Manager\sgtray.exe" [2003-02-13 155648]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2003-08-23 151597]
"Recguard"="c:\windows\SMINST\RECGUARD.EXE" [2002-09-14 212992]
"NvCplDaemon"="c:\windows\System32\NvCpl.dll" [2003-05-03 4640768]
"nwiz"="nwiz.exe" [2003-05-03 323584]
"PS2"="c:\windows\system32\ps2.exe" [2002-10-16 81920]
"HPDJ Taskbar Utility"="c:\windows\System32\spool\drivers\w32x86\3\hpztsb05.exe" [2002-03-18 188416]
"DIGStream"="c:\program files\DIGStream\digstream.exe" [2005-05-18 282624]
"Microsoft Works Update Detection"="c:\program files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe" [2002-07-17 28672]
"IgfxTray"="c:\windows\System32\igfxtray.exe" [2004-08-20 155648]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2005-12-21 278528]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2006-01-21 155648]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"nesurukeb"="c:\windows\system32\tohuzeno.dll" [BU]
"derirowaki"="wezahevu.dll" [BU]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Configuration Utility.lnk - c:\program files\MA311 PCI Adapter Configuration Utility\wlanutil.exe [2003-12-12 625152]
Event Reminder.lnk - c:\program files\Broderbund\PrintMaster\PMremind.exe [2008-9-13 331776]
HP Digital Imaging Monitor.lnk - c:\program files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe [2003-6-13 233472]
Updates from HP.lnk - c:\program files\Updates from HP\137903\Program\BackWeb-137903.exe [2003-8-23 16384]
WinZip Quick Pick.lnk - c:\program files\WinZip\WZQKPICK.EXE [2006-1-28 122880]

[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoSetActiveDesktop"= 1 (0x1)
"NoActiveDesktopChanges"= 1 (0x1)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\OPXPGina]
2003-02-21 10:50 40960 —-a-w- c:\program files\Softex\OmniPass\OPXPGina.dll

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Updates from HP\\137903\\Program\\BackWeb-137903.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Documents and Settings\\Owner\\My Documents\\PCDnldSvr\\PCDnldServer.exe"=

R3 MA311;NETGEAR Wireless LAN Driver;c:\windows\system32\drivers\ma311n51.sys [2003-12-12 7:08 PM 54784]
S3 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [2007-11-06 3:22 PM 34064]
.
Contents of the 'Scheduled Tasks' folder

2004-01-09 c:\windows\Tasks\Symantec NetDetect.job
- c:\program files\Symantec\LiveUpdate\NDETECT.EXE [2003-08-29 19:20]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.yahoo.com/
uDefault_Search_URL = hxxp://srch-us9.hpwis.com/
mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride = localhost
uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ie/defaults/su/msgr8/*http://www.yahoo.com
IE: &Google Search - c:\program files\google\GoogleToolbar2.dll/cmsearch.html
IE: &Translate English Word - c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html
IE: &Yahoo! Search - file:///c:\program files\Yahoo!\Common/ycsrch.htm
IE: Backward Links - c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
IE: Cached Snapshot of Page - c:\program files\google\GoogleToolbar2.dll/cmcache.html
IE: Similar Pages - c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
IE: Translate Page into English - c:\program files\google\GoogleToolbar2.dll/cmtrans.html
IE: Yahoo! &Dictionary - file:///c:\program files\Yahoo!\Common/ycdict.htm
IE: Yahoo! &Maps - file:///c:\program files\Yahoo!\Common/ycmap.htm
IE: Yahoo! &SMS - file:///c:\program files\Yahoo!\Common/ycsms.htm
LSP: SpSubLSP.dll
Trusted Zone: turbotax.com
DPF: DirectAnimation Java Classes - file://c:\windows\Java\classes\dajava.cab
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
FF - ProfilePath - c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\etmra113.default\
FF - prefs.js: browser.startup.homepage - www.google.com
FF - plugin: c:\program files\Mozilla Firefox\plugins\NPCIG.dll
FF - plugin: c:\program files\Real\RealOne Player\Netscape6\nppl3260.dll
FF - plugin: c:\program files\Real\RealOne Player\Netscape6\nprjplug.dll
FF - plugin: c:\program files\Real\RealOne Player\Netscape6\nprpjplug.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-01-30 20:50
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(584)
c:\program files\Softex\OmniPass\opxpgina.dll

- - - - - - - > 'lsass.exe'(640)
c:\windows\system32\SpSubLSP.dll

- - - - - - - > 'explorer.exe'(3772)
c:\windows\system32\WININET.dll
c:\docume~1\Owner\LOCALS~1\Temp\IadHide4.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\mshtml.dll
c:\windows\system32\msls31.dll
c:\windows\system32\webcheck.dll
c:\progra~1\PANICW~1\POP-UP~1\XAHook.dll
.
———————— Other Running Processes ————————
.
c:\program files\Common Files\Intuit\Update Service\IntuitUpdateService.exe
c:\program files\Softex\OmniPass\Omniserv.exe
c:\program files\Softex\OmniPass\OPXPApp.exe
c:\program files\Canon\CAL\CALMAIN.exe
c:\windows\system32\wscntfy.exe
c:\program files\Hewlett-Packard\Digital Imaging\Unload\hpqcmon.exe
c:\program files\iPod\bin\iPodService.exe
c:\program files\Common Files\Real\Update_OB\rnathchk.exe
c:\program files\Java\jre1.6.0_07\bin\jucheck.exe
.
**************************************************************************
.
Completion time: 2010-01-30 21:02:02 - machine was rebooted
ComboFix-quarantined-files.txt 2010-01-31 02:01
ComboFix2.txt 2010-01-31 01:14
ComboFix3.txt 2010-01-30 16:16
ComboFix4.txt 2008-09-03 23:34

Pre-Run: 51,236,687,872 bytes free
Post-Run: 51,204,382,720 bytes free

- - End Of File - - 3B86E24FB3F8D1B2A344D73EC12FB64D




Malwarebytes' Anti-Malware 1.44
Database version: 3667
Windows 5.1.2600 Service Pack 2
Internet Explorer 8.0.6001.18702

2010-01-31 8:39:45 AM
mbam-log-2010-01-31 (08-39-45).txt

Scan type: Quick Scan
Objects scanned: 115008
Time elapsed: 7 minute(s), 54 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 2
Registry Values Infected: 2
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 1

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{a072ec12-a40b-41dd-9a1a-cdb848b70f3c} (Rogue.Installer) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{bd4f7a6d-0107-4bdf-b72b-021b717b06ce} (Trojan.FakeAlert) -> Quarantined and deleted successfully.

Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\nesurukeb (Trojan.Vundo.H) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\derirowaki (Trojan.Vundo) -> Quarantined and deleted successfully.

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
C:\WINDOWS\system32\fipuyuko.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully.
Hi maldini,

Looks better. Please try to run OTL.

  • Double click on OTL.exe to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output
  • Check the boxes beside LOP Check and Purity Check.
  • In the Extra Registry section, make sure it is set to All.
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.

Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply. You may need two posts to fit them all in.

Thanks
Hi Oldman, I downloaded a new version of OTL but I am still having the exact same problem as I did the first time I ran it. It does not complete. A few minutes into scanning it brings up a pop up window with the following statement 2099/1/1 12:00 is not a valid date and time And then hangs on the following: Looking for newly created files: C:\WINDOWS\System32\naruzisa…
Hi maldini,

Check your clock and make sure it is set correctly.

Right click on the clock, click Adjust Date/Time. Adjust the date accordingly. Try OTL again.

If it still won't work


Please download DDS and save it to your desktop.
  • Disable any script blocking protection
  • Double click dds.scr to run the tool.
  • When done, DDS.txt will open.
  • Click Yes at the next prompt for Optional Scan.
  • Save both reports to your desktop.
—————————————————

Please include the contents of the following in your next reply:

DDS.txt

Please attach the second file; Attach.txt. To attach a file, do the following:
  • Under the reply panel is the Attachments Panel
  • Browse for the attachment file you want to upload, then click the green Upload button
  • Once it has uploaded, click the Manage Current Attachments drop down box
  • Click on [external image: Posted Image] to insert the attachment into your post
I checked the time settings and they were correct. I reran OTL just in case and it hung in the same spot again. Here are the DDS logs Andy DDS (Ver_09-12-01.01) - NTFSx86 Run by [removed] at 17:41:11.15 on 2010-01-31 Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_07 Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.247.61 [GMT -5:00] ============== Running Processes =============== C:\WINDOWS\system32\svchost -k DcomLaunch svchost.exe C:\WINDOWS\System32\svchost.exe -k netsvcs svchost.exe svchost.exe C:\WINDOWS\system32\spoolsv.exe svchost.exe C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe C:\Program Files\Softex\OmniPass\Omniserv.exe C:\WINDOWS\System32\svchost.exe -k imgsvc C:\Program Files\Softex\OmniPass\OPXPApp.exe C:\Program Files\Canon\CAL\CALMAIN.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\wscntfy.exe C:\windows\system\hpsysdrv.exe C:\Program Files\Hewlett-Packard\Digital Imaging\Unload\hpqcmon.exe C:\Program Files\HP\HP Software Update\HPWuSchd.exe C:\WINDOWS\System32\hphmon05.exe C:\HP\KBD\KBD.EXE C:\Program Files\Common Files\Real\Update_OB\realsched.exe C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb05.exe C:\Program Files\DIGStream\digstream.exe C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe C:\WINDOWS\System32\igfxtray.exe C:\Program Files\iTunes\iTunesHelper.exe C:\Program Files\QuickTime\qttask.exe C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe C:\PROGRA~1\PANICW~1\POP-UP~1\PSFree.exe C:\Program Files\Common Files\Real\Update_OB\rnathchk.exe C:\PROGRA~1\WALGRE~1\WALGRE~1\data\Xtras\mssysmgr.exe C:\Program Files\iPod\bin\iPodService.exe C:\Program Files\MA311 PCI Adapter Configuration Utility\wlanutil.exe C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe C:\Program Files\Updates from HP\137903\Program\BackWeb-137903.exe C:\Program Files\WinZip\WZQKPICK.EXE C:\WINDOWS\system32\wuauclt.exe C:\Program Files\Java\jre1.6.0_07\bin\jucheck.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\Documents and Settings\Owner\Desktop\dds.scr ============== Pseudo HJT Report =============== uStart Page = hxxp://www.yahoo.com/ uDefault_Search_URL = hxxp://srch-us9.hpwis.com/ mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html uInternet Connection Wizard,ShellNext = iexplore uInternet Settings,ProxyOverride = localhost uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ie/defaults/su/msgr8/*http://www.yahoo.com uURLSearchHooks: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn\yt.dll BHO: Yahoo! Toolbar Helper: {02478d38-c3f9-4efb-9b51-7695eca05670} - c:\program files\yahoo!\companion\installs\cpn\yt.dll BHO: AcroIEHlprObj Class: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 6.0\reader\activex\AcroIEHelper.dll BHO: {243b17de-77c7-46bf-b94b-0b5f309a0e64} - c:\program files\microsoft money\system\mnyside.dll BHO: Yahoo! IE Services Button: {5bab4b5b-68bc-4b02-94d6-2fc0de4a7897} - c:\program files\yahoo!\common\yiesrvc.dll BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre1.6.0_07\bin\ssv.dll BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\googletoolbar2.dll TB: HP View: {b2847e28-5d7d-4deb-8b67-05d28bcf79f5} - c:\program files\hewlett-packard\digital imaging\bin\hpdtlk02.dll TB: &Google: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\googletoolbar2.dll TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn\yt.dll EB: {32683183-48a0-441b-a342-7c2a440a9478} - No File uRun: [BackupNotify] c:\program files\hewlett-packard\digital imaging\bin\backupnotify.exe uRun: [NVIEW] rundll32.exe nview.dll,nViewLoadHook uRun: [PopUpStopperFreeEdition] "c:\progra~1\panicw~1\pop-up~1\PSFree.exe" uRun: [RealPlayer] "c:\program files\real\realone player\realplay.exe" /RunUPGToolCommandReBoot uRun: [PhotoShow Deluxe Media Manager] c:\progra~1\walgre~1\walgre~1\data\xtras\mssysmgr.exe mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe mRun: [hpsysdrv] c:\windows\system\hpsysdrv.exe mRun: [CamMonitor] c:\program files\hewlett-packard\digital imaging\\unload\hpqcmon.exe mRun: [HP Software Update] "c:\program files\hp\hp software update\HPWuSchd.exe" mRun: [HPHUPD05] c:\program files\hewlett-packard\{45b6180b-dcab-4093-8ee8-6164457517f0}\hphupd05.exe mRun: [HPHmon05] c:\windows\system32\hphmon05.exe mRun: [KBD] c:\hp\kbd\KBD.EXE mRun: [StorageGuard] "c:\program files\common files\sonic\update manager\sgtray.exe" /r mRun: [TkBellExe] "c:\program files\common files\real\update_ob\realsched.exe" -osboot mRun: [Recguard] c:\windows\sminst\RECGUARD.EXE mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup mRun: [nwiz] nwiz.exe /installquiet /keeploaded /nodetect mRun: [PS2] c:\windows\system32\ps2.exe mRun: [HPDJ Taskbar Utility] c:\windows\system32\spool\drivers\w32x86\3\hpztsb05.exe mRun: [DIGStream] c:\program files\digstream\digstream.exe mRun: [Microsoft Works Update Detection] c:\program files\common files\microsoft shared\works shared\WkUFind.exe mRun: [IgfxTray] c:\windows\system32\igfxtray.exe mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe" mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime mRun: [SunJavaUpdateSched] "c:\program files\java\jre1.6.0_07\bin\jusched.exe" StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\config~1.lnk - c:\program files\ma311 pci adapter configuration utility\wlanutil.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\eventr~1.lnk - c:\program files\broderbund\printmaster\PMremind.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\hpdigi~1.lnk - c:\program files\hewlett-packard\digital imaging\bin\hpqtra08.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\update~1.lnk - c:\program files\updates from hp\137903\program\BackWeb-137903.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\winzip~1.lnk - c:\program files\winzip\WZQKPICK.EXE dPolicies-explorer: NoSetActiveDesktop = 1 (0x1) dPolicies-explorer: NoActiveDesktopChanges = 1 (0x1) IE: &Google Search - c:\program files\google\GoogleToolbar2.dll/cmsearch.html IE: &Translate English Word - c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html IE: &Yahoo! Search - file:///c:\program files\yahoo!\Common/ycsrch.htm IE: Backward Links - c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html IE: Cached Snapshot of Page - c:\program files\google\GoogleToolbar2.dll/cmcache.html IE: Similar Pages - c:\program files\google\GoogleToolbar2.dll/cmsimilar.html IE: Translate Page into English - c:\program files\google\GoogleToolbar2.dll/cmtrans.html IE: Yahoo! &Dictionary - file:///c:\program files\yahoo!\Common/ycdict.htm IE: Yahoo! &Maps - file:///c:\program files\yahoo!\Common/ycmap.htm IE: Yahoo! &SMS - file:///c:\program files\yahoo!\Common/ycsms.htm IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBC} - c:\program files\java\jre1.6.0_07\bin\ssv.dll IE: {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - c:\program files\yahoo!\common\yiesrvc.dll IE: {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - {DD6687B5-CB43-4211-BFC9-2942CCBDCB3E} - c:\program files\microsoft money\system\mnyside.dll LSP: SpSubLSP.dll Trusted Zone: turbotax.com DPF: DirectAnimation Java Classes - file://c:\windows\java\classes\dajava.cab DPF: Microsoft XML Parser for Java - file://c:\windows\java\classes\xmldso.cab DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} - c:\program files\yahoo!\common\yinsthelper.dll DPF: {31435657-9980-0010-8000-00AA00389B71} - hxxp://download.microsoft.com/download/e/2/f/e2fcec4b-6c8b-48b7-adab-ab9c403a978f/wvc1dmo.cab DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab DPF: {B160422D-0A48-11D4-BD9B-00A0C9B0AB7B} - hxxp://expressit.broderbund.com/plugin/Download.cab DPF: {CAFEEFAC-0014-0001-0002-ABCDEFFEDCBA} - hxxp://java.sun.com/products/plugin/1.4/jinstall-14_02-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab Handler: cdo - {CD00020A-8B95-11D1-82DB-00C04FB1625D} - c:\program files\common files\microsoft shared\web folders\PKMCDO.DLL Notify: igfxcui - igfxsrvc.dll Notify: OPXPGina - c:\program files\softex\omnipass\opxpgina.dll ================= FIREFOX =================== FF - ProfilePath - c:\docume~1\owner\applic~1\mozilla\firefox\profiles\etmra113.default\ FF - prefs.js: browser.startup.homepage - www.google.com FF - plugin: c:\program files\mozilla firefox\plugins\NPCIG.dll FF - plugin: c:\program files\real\realone player\netscape6\nppl3260.dll FF - plugin: c:\program files\real\realone player\netscape6\nprjplug.dll FF - plugin: c:\program files\real\realone player\netscape6\nprpjplug.dll FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\ FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} ============= SERVICES / DRIVERS =============== R3 MA311;NETGEAR Wireless LAN Driver;c:\windows\system32\drivers\ma311n51.sys [2003-12-12 54784] S3 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [2007-11-6 34064] =============== Created Last 30 ================ 2010-01-31 13:26:26 0 d—–w- c:\docume~1\owner\applic~1\Malwarebytes 2010-01-31 13:26:13 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys 2010-01-31 13:26:11 0 d—–w- c:\docume~1\alluse~1\applic~1\Malwarebytes 2010-01-31 13:26:10 19160 —-a-w- c:\windows\system32\drivers\mbam.sys 2010-01-31 13:26:09 0 d—–w- c:\program files\Malwarebytes' Anti-Malware 2010-01-30 15:22:26 77312 —-a-w- c:\windows\MBR.exe 2010-01-30 15:22:26 261632 —-a-w- c:\windows\PEV.exe 2010-01-30 15:22:25 98816 —-a-w- c:\windows\sed.exe 2010-01-30 15:22:25 161792 —-a-w- c:\windows\SWREG.exe 2010-01-27 15:39:09 0 d-sh–w- c:\documents and settings\owner\IECompatCache ==================== Find3M ==================== 2009-12-21 19:14:05 916480 ——w- c:\windows\system32\wininet.dll ============= FINISH: 17:42:31.25 =============== 📎Attach.txt

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI