This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Closed] HijackThis Log and post Security-Tool virus problems

15 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

hmmm

not happy with that though…let's see if we can figure out the issue.

delete the copy of combofix that you have on your desktop…download a fresh copy from the following link:

disable your security programs and run it - post the resulting log:

Link 1
ComboFix 10-02-26.02 - Drew 02/27/2010 2:39.3.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.1519.1125 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFixx.exe
.

((((((((((((((((((((((((( Files Created from 2010-01-27 to 2010-02-27 )))))))))))))))))))))))))))))))
.

2010-02-26 07:11 . 2010-02-26 07:12 ——– d—–w- c:\documents and settings\Drew\Local Settings\Application Data\Temp
2010-02-25 23:40 . 2010-02-25 23:40 ——– d—–w- C:\_OTM
2010-02-25 21:46 . 2010-02-25 21:46 ——– d—–w- c:\program files\ESET
2010-02-25 20:06 . 2010-02-25 20:06 ——– d—–w- c:\documents and settings\Drew\Application Data\Malwarebytes
2010-02-25 20:06 . 2010-01-07 21:07 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-02-25 20:06 . 2010-02-25 20:06 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes
2010-02-25 20:06 . 2010-02-25 20:06 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2010-02-25 20:06 . 2010-01-07 21:07 19160 —-a-w- c:\windows\system32\drivers\mbam.sys
2010-02-24 03:52 . 2010-02-27 07:37 ——– d—–w- c:\documents and settings\Drew\Application Data\mIRC
2010-02-24 03:52 . 2010-02-26 18:24 ——– d—–w- c:\program files\mIRC
2010-02-23 13:02 . 2010-02-23 13:02 ——– d—–w- c:\program files\MSECACHE
2010-02-23 06:50 . 2010-02-23 06:50 ——– d—–w- c:\program files\JRE
2010-02-23 06:28 . 2010-02-23 06:46 ——– d—–w- c:\program files\Eusing Free Registry Cleaner
2010-02-22 20:24 . 2010-02-23 06:52 ——– d—–w- c:\program files\Common Files\Java
2010-02-15 07:04 . 2010-02-24 23:48 ——– d—–w- c:\program files\NetDraft
2010-02-14 22:09 . 2010-02-25 21:27 1 —-a-w- c:\documents and settings\Drew\Application Data\OpenOffice.org\3\user\uno_packages\cache\stamp.sys
2010-02-14 22:09 . 2010-02-14 22:09 ——– d—–w- c:\documents and settings\Drew\Application Data\OpenOffice.org
2010-02-14 22:02 . 2010-02-14 22:02 ——– d—–w- c:\program files\OpenOffice.org 3
2010-02-14 22:02 . 2010-02-14 22:01 411368 —-a-w- c:\windows\system32\deploytk.dll
2010-02-08 19:41 . 2010-02-23 06:49 ——– d—–w- c:\program files\Magic Workstation2
2010-02-08 19:34 . 2010-02-08 19:34 ——– d—–w- c:\program files\Trend Micro
2010-02-05 18:57 . 2010-02-05 18:57 ——– d—–w- c:\documents and settings\Drew\Application Data\acccore
2010-02-05 18:56 . 2010-02-05 18:56 ——– d—–w- c:\documents and settings\Drew\Local Settings\Application Data\AOL
2010-02-05 18:55 . 2010-02-05 18:55 ——– d—–w- c:\documents and settings\Drew\Local Settings\Application Data\AOL OCP
2010-02-05 18:55 . 2010-02-05 18:55 ——– d—–w- c:\documents and settings\All Users\Application Data\acccore
2010-02-05 18:54 . 2010-02-05 18:57 ——– d—–w- c:\documents and settings\All Users\Application Data\AOL OCP
2010-02-05 18:54 . 2010-02-05 18:54 ——– d—–w- c:\documents and settings\All Users\Application Data\AOL
2010-02-05 18:54 . 2010-02-05 18:54 ——– d—–w- c:\program files\Common Files\AOL
2010-02-05 18:54 . 2010-02-05 18:56 ——– d—–w- c:\program files\AIM6
2010-01-28 22:11 . 2010-01-28 22:11 ——– d—–w- c:\documents and settings\NetworkService\Local Settings\Application Data\Google
2010-01-28 22:06 . 2010-01-28 22:06 ——– d—–w- c:\documents and settings\LocalService\Local Settings\Application Data\Google

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-02-27 06:21 . 2006-11-09 23:12 ——– d—–w- c:\program files\Magic Workstation
2010-02-25 20:18 . 2005-09-16 19:54 ——– d—–w- c:\program files\Lx_cats
2010-02-23 06:52 . 2008-06-23 01:23 ——– d—–w- c:\program files\Spybot - Search & Destroy
2010-02-23 06:51 . 2005-07-13 21:52 ——– d–h–w- c:\program files\InstallShield Installation Information
2010-02-23 06:47 . 2008-06-23 01:23 ——– d—–w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2010-02-15 09:04 . 2005-07-16 22:30 22032 -c–a-w- c:\documents and settings\Drew\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-02-05 18:55 . 2005-07-11 00:55 ——– d—–w- c:\documents and settings\All Users\Application Data\Viewpoint
2010-02-05 18:53 . 2005-07-11 00:55 ——– d—–w- c:\program files\AIM
2010-01-28 22:06 . 2007-09-27 22:41 ——– d—–w- c:\program files\Google
2010-01-27 11:08 . 2010-01-27 11:08 ——– d—–w- c:\program files\MSBuild
2010-01-27 11:07 . 2010-01-27 11:07 ——– d—–w- c:\program files\Reference Assemblies
2010-01-27 11:02 . 2010-01-27 11:02 ——– d—–w- c:\program files\MSXML 6.0
2010-01-05 10:00 . 2004-08-04 12:00 832512 ——w- c:\windows\system32\wininet.dll
2010-01-05 10:00 . 2004-08-04 12:00 78336 —-a-w- c:\windows\system32\ieencode.dll
2010-01-05 10:00 . 2004-08-04 12:00 17408 —-a-w- c:\windows\system32\corpol.dll
2009-12-31 16:14 . 2004-08-04 12:00 352640 —-a-w- c:\windows\system32\drivers\srv.sys
2009-12-16 12:58 . 2005-07-10 20:11 343040 —-a-w- c:\windows\system32\mspaint.exe
2009-12-14 07:35 . 2004-08-04 12:00 33280 —-a-w- c:\windows\system32\csrsrv.dll
2009-12-08 18:55 . 2004-08-04 12:00 2180352 ——w- c:\windows\system32\ntoskrnl.exe
2009-12-08 18:19 . 2004-08-03 22:59 2057728 ——w- c:\windows\system32\ntkrnlpa.exe
2009-12-04 14:41 . 2004-08-04 12:00 453760 —-a-w- c:\windows\system32\drivers\mrxsmb.sys
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2010-01-27 39408]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AlcxMonitor"="ALCXMNTR.EXE" [2004-09-07 57344]
"LXCCCATS"="c:\windows\System32\spool\DRIVERS\W32X86\3\LXCCtime.dll" [2005-01-10 69632]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-01-11 246504]

c:\documents and settings\Drew\Start Menu\Programs\Startup\
OpenOffice.org 3.2.lnk - c:\program files\OpenOffice.org 3\program\quickstart.exe [2009-12-15 384000]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk.disabled [2005-7-16 1757]
NkvMon.exe.lnk.disabled [2005-8-30 1567]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"ctfmon.exe"=c:\windows\system32\ctfmon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"FaxCenterServer"="c:\program files\Lexmark Fax Solutions\fm3032.exe" /s
"LXCCCATS"=rundll32 c:\windows\System32\spool\DRIVERS\W32X86\3\LXCCtime.dll,_RunDLLEntry@16
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" -atboottime
"lxccmon.exe"="c:\program files\Lexmark 3300 Series\lxccmon.exe"

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Apprentice\\Appr.exe"=
"c:\\Program Files\\AIM\\aim.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"c:\\Program Files\\Magic Workstation\\MWSPlay.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\AIM6\\aim6.exe"=
"c:\\Program Files\\NetDraft\\NETDRAFT.EXE"=
"c:\\Program Files\\mIRC\\mirc.exe"=

R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [1/10/2007 2:15 PM 24652]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [1/28/2010 5:06 PM 135664]
.
Contents of the 'Scheduled Tasks' folder

2010-02-27 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-01-28 22:06]

2010-02-27 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-01-28 22:06]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.com/
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html
uInternet Connection Wizard,ShellNext = iexplore
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-02-27 02:46
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
LXCCCATS = rundll32 c:\windows\System32\spool\DRIVERS\W32X86\3\LXCCtime.dll,_RunDLLEntry@16???????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'explorer.exe'(3116)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
.
Completion time: 2010-02-27 02:49:19
ComboFix-quarantined-files.txt 2010-02-27 07:49
ComboFix2.txt 2010-02-24 22:12
ComboFix3.txt 2010-02-24 03:27

Pre-Run: 22,741,532,672 bytes free
Post-Run: 23,362,727,936 bytes free

- - End Of File - - 938A448AA33274E3813798D5C89A6188



I got a few error messages as Combofix was finishing up, saying that "Windows Explorer" had a problem and was shutting down. Again, I dont know if this is relevant.

Thank you, again. I'm in a bit of debt right now, but as soon as I can get out of it, I'm making a donation to this site.

Drew
OK,

Let's get rid of all the Java entries that I see, then we can start again.

Also, I am not seeing an Antivirus - which is essential.

Download and install this one - it's excellent and it's free:

Microsoft Security Essentials


NEXT



  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below.
  • They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
Copy/paste the text inside the Codebox below into notepad:

Here's how to do that:
Click Start > Run type Notepad click OK.
This will open an empty notepad file:

Copy all the text inside of the code box - Press Ctrl+C (or right click on the highlighted section and choose 'copy')

Folder::
c:\program files\Common Files\Java
C:\Program Files\Java
c:\documents and settings\Drew\Application Data\Sun\Java

File::
c:\program files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Java\jre6\bin\ssv.dll
C:\Program Files\Java\jre6\bin\jp2ssv.dll
C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Java\jre6\bin\jp2iexp.dll

DDS::
BHO: {dbc80044-a445-435b-bc74-9c25c1c588a9} - Java™ Plug-In 2 SSV Helper

Registry::
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"=-

Now paste the copied text into the open notepad - press CTRL+V (or right click and choose 'paste')

Save this file to your desktop, Save this as "CFScript"


Here's how to do that:

1.Click File;
2.Click Save As… Change the directory to your desktop;
3.Change the Save as type to "All Files";
4.Type in the file name: CFScript
5.Click Save …

[external image: Posted Image]
  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you.
  • Copy and paste the contents of the log in your next reply.

CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.

Make sure you reboot:

Now try and download Java again and install:

http://www.java.com/en/download/index.jsp
Ran Combofix again, here is the log:

ComboFix 10-02-26.03 - Drew 02/27/2010 11:02:09.4.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.1519.1092 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFixx.exe
Command switches used :: c:\documents and settings\Drew\Desktop\CFScript.txt

FILE ::
"c:\program files\Common Files\Java\Java Update\jusched.exe"
"c:\program files\Java\jre6\bin\jp2iexp.dll"
"c:\program files\Java\jre6\bin\jp2ssv.dll"
"c:\program files\Java\jre6\bin\jqs.exe"
"c:\program files\Java\jre6\bin\jusched.exe"
"c:\program files\Java\jre6\bin\ssv.dll"
"c:\program files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll"
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\Drew\Application Data\Sun\Java
c:\documents and settings\Drew\Application Data\Sun\Java\AU\au.cab
c:\documents and settings\Drew\Application Data\Sun\Java\AU\au.msi
c:\documents and settings\Drew\Application Data\Sun\Java\jre1.6.0_18\OpenOffice_banner.jpg
c:\program files\Common Files\Java
c:\program files\Common Files\Java\Java Update\jaucheck.exe
c:\program files\Common Files\Java\Java Update\jaureg.exe
c:\program files\Common Files\Java\Java Update\jucheck.exe
c:\program files\Common Files\Java\Java Update\jusched.exe
c:\program files\Common Files\Java\Java Update\task.xml
c:\program files\Common Files\Java\Java Update\task64.xml

.
((((((((((((((((((((((((( Files Created from 2010-01-27 to 2010-02-27 )))))))))))))))))))))))))))))))
.

2010-02-27 15:52 . 2010-02-27 15:52 ——– d—–w- c:\windows\LastGood
2010-02-27 08:40 . 2010-02-27 08:40 20172 —ha-w- c:\windows\system32\mlfcache.dat
2010-02-26 07:11 . 2010-02-26 07:12 ——– d—–w- c:\documents and settings\Drew\Local Settings\Application Data\Temp
2010-02-25 23:40 . 2010-02-25 23:40 ——– d—–w- C:\_OTM
2010-02-25 21:46 . 2010-02-25 21:46 ——– d—–w- c:\program files\ESET
2010-02-25 20:06 . 2010-02-25 20:06 ——– d—–w- c:\documents and settings\Drew\Application Data\Malwarebytes
2010-02-25 20:06 . 2010-01-07 21:07 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-02-25 20:06 . 2010-02-25 20:06 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes
2010-02-25 20:06 . 2010-02-25 20:06 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2010-02-25 20:06 . 2010-01-07 21:07 19160 —-a-w- c:\windows\system32\drivers\mbam.sys
2010-02-24 03:52 . 2010-02-27 08:47 ——– d—–w- c:\documents and settings\Drew\Application Data\mIRC
2010-02-24 03:52 . 2010-02-27 08:25 ——– d—–w- c:\program files\mIRC
2010-02-23 13:02 . 2010-02-23 13:02 ——– d—–w- c:\program files\MSECACHE
2010-02-23 06:50 . 2010-02-23 06:50 ——– d—–w- c:\program files\JRE
2010-02-23 06:28 . 2010-02-23 06:46 ——– d—–w- c:\program files\Eusing Free Registry Cleaner
2010-02-15 07:04 . 2010-02-24 23:48 ——– d—–w- c:\program files\NetDraft
2010-02-14 22:09 . 2010-02-25 21:27 1 —-a-w- c:\documents and settings\Drew\Application Data\OpenOffice.org\3\user\uno_packages\cache\stamp.sys
2010-02-14 22:09 . 2010-02-14 22:09 ——– d—–w- c:\documents and settings\Drew\Application Data\OpenOffice.org
2010-02-14 22:02 . 2010-02-14 22:02 ——– d—–w- c:\program files\OpenOffice.org 3
2010-02-14 22:02 . 2010-02-14 22:01 411368 —-a-w- c:\windows\system32\deploytk.dll
2010-02-08 19:41 . 2010-02-23 06:49 ——– d—–w- c:\program files\Magic Workstation2
2010-02-08 19:34 . 2010-02-08 19:34 ——– d—–w- c:\program files\Trend Micro
2010-02-05 18:57 . 2010-02-05 18:57 ——– d—–w- c:\documents and settings\Drew\Application Data\acccore
2010-02-05 18:56 . 2010-02-05 18:56 ——– d—–w- c:\documents and settings\Drew\Local Settings\Application Data\AOL
2010-02-05 18:55 . 2010-02-05 18:55 ——– d—–w- c:\documents and settings\Drew\Local Settings\Application Data\AOL OCP
2010-02-05 18:55 . 2010-02-05 18:55 ——– d—–w- c:\documents and settings\All Users\Application Data\acccore
2010-02-05 18:54 . 2010-02-05 18:57 ——– d—–w- c:\documents and settings\All Users\Application Data\AOL OCP
2010-02-05 18:54 . 2010-02-05 18:54 ——– d—–w- c:\documents and settings\All Users\Application Data\AOL
2010-02-05 18:54 . 2010-02-05 18:54 ——– d—–w- c:\program files\Common Files\AOL
2010-02-05 18:54 . 2010-02-05 18:56 ——– d—–w- c:\program files\AIM6
2010-01-28 22:11 . 2010-01-28 22:11 ——– d—–w- c:\documents and settings\NetworkService\Local Settings\Application Data\Google
2010-01-28 22:06 . 2010-01-28 22:06 ——– d—–w- c:\documents and settings\LocalService\Local Settings\Application Data\Google

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-02-27 06:21 . 2006-11-09 23:12 ——– d—–w- c:\program files\Magic Workstation
2010-02-25 20:18 . 2005-09-16 19:54 ——– d—–w- c:\program files\Lx_cats
2010-02-23 06:52 . 2008-06-23 01:23 ——– d—–w- c:\program files\Spybot - Search & Destroy
2010-02-23 06:51 . 2005-07-13 21:52 ——– d–h–w- c:\program files\InstallShield Installation Information
2010-02-23 06:47 . 2008-06-23 01:23 ——– d—–w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2010-02-15 09:04 . 2005-07-16 22:30 22032 -c–a-w- c:\documents and settings\Drew\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-02-05 18:55 . 2005-07-11 00:55 ——– d—–w- c:\documents and settings\All Users\Application Data\Viewpoint
2010-02-05 18:53 . 2005-07-11 00:55 ——– d—–w- c:\program files\AIM
2010-01-28 22:06 . 2007-09-27 22:41 ——– d—–w- c:\program files\Google
2010-01-27 11:08 . 2010-01-27 11:08 ——– d—–w- c:\program files\MSBuild
2010-01-27 11:07 . 2010-01-27 11:07 ——– d—–w- c:\program files\Reference Assemblies
2010-01-27 11:02 . 2010-01-27 11:02 ——– d—–w- c:\program files\MSXML 6.0
2010-01-05 10:00 . 2004-08-04 12:00 832512 ——w- c:\windows\system32\wininet.dll
2010-01-05 10:00 . 2004-08-04 12:00 78336 —-a-w- c:\windows\system32\ieencode.dll
2010-01-05 10:00 . 2004-08-04 12:00 17408 —-a-w- c:\windows\system32\corpol.dll
2009-12-31 16:14 . 2004-08-04 12:00 352640 —-a-w- c:\windows\system32\drivers\srv.sys
2009-12-16 12:58 . 2005-07-10 20:11 343040 —-a-w- c:\windows\system32\mspaint.exe
2009-12-14 07:35 . 2004-08-04 12:00 33280 —-a-w- c:\windows\system32\csrsrv.dll
2009-12-08 18:55 . 2004-08-04 12:00 2180352 ——w- c:\windows\system32\ntoskrnl.exe
2009-12-08 18:19 . 2004-08-03 22:59 2057728 ——w- c:\windows\system32\ntkrnlpa.exe
2009-12-04 14:41 . 2004-08-04 12:00 453760 —-a-w- c:\windows\system32\drivers\mrxsmb.sys
.

((((((((((((((((((((((((((((( SnapShot@2010-02-27_07.46.30 )))))))))))))))))))))))))))))))))))))))))
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2010-01-27 39408]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AlcxMonitor"="ALCXMNTR.EXE" [2004-09-07 57344]
"LXCCCATS"="c:\windows\System32\spool\DRIVERS\W32X86\3\LXCCtime.dll" [2005-01-10 69632]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2006-06-30 77824]

c:\documents and settings\Drew\Start Menu\Programs\Startup\
OpenOffice.org 3.2.lnk - c:\program files\OpenOffice.org 3\program\quickstart.exe [2009-12-15 384000]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk.disabled [2005-7-16 1757]
NkvMon.exe.lnk.disabled [2005-8-30 1567]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"ctfmon.exe"=c:\windows\system32\ctfmon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"FaxCenterServer"="c:\program files\Lexmark Fax Solutions\fm3032.exe" /s
"LXCCCATS"=rundll32 c:\windows\System32\spool\DRIVERS\W32X86\3\LXCCtime.dll,_RunDLLEntry@16
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" -atboottime
"lxccmon.exe"="c:\program files\Lexmark 3300 Series\lxccmon.exe"

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Apprentice\\Appr.exe"=
"c:\\Program Files\\AIM\\aim.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"c:\\Program Files\\Magic Workstation\\MWSPlay.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\AIM6\\aim6.exe"=
"c:\\Program Files\\NetDraft\\NETDRAFT.EXE"=
"c:\\Program Files\\mIRC\\mirc.exe"=

R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [1/10/2007 2:15 PM 24652]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [1/28/2010 5:06 PM 135664]
.
Contents of the 'Scheduled Tasks' folder

2010-02-27 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-01-28 22:06]

2010-02-27 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-01-28 22:06]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.com/
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html
uInternet Connection Wizard,ShellNext = iexplore
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-02-27 11:04
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
LXCCCATS = rundll32 c:\windows\System32\spool\DRIVERS\W32X86\3\LXCCtime.dll,_RunDLLEntry@16???????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2010-02-27 11:07:23
ComboFix-quarantined-files.txt 2010-02-27 16:07
ComboFix2.txt 2010-02-27 07:49
ComboFix3.txt 2010-02-24 22:12
ComboFix4.txt 2010-02-24 03:27

Pre-Run: 23,206,334,464 bytes free
Post-Run: 23,248,977,920 bytes free

- - End Of File - - 6466D5FBE42AA7480CFE8E92653E3037




I tried installing Java again.. and again, no dice. Only now, instead of the "Downloading Installer" box coming up and disappearing and nothing happening, it pops up, disappears, and I get a message box "Abort - Java™ Installer" with the text "To restart the Java™ installer, please refresh the web page"

Also, I was unable to download the antivirus you suggested, I'm going to try again now that I've ran Combofix again.

Thanks again,
Drew
OK

Clean out all your temp folders first:

do this


Download TFC to your desktop
  • Close any open windows.
  • Double click the TFC icon to run the program
  • TFC will close all open programs itself in order to run,
  • Click the Start button to begin the process.
  • Allow TFC to run uninterrupted.
  • The program should not take long to finish it's job
  • Once its finished it should automatically reboot your machine,
  • if it doesn't, manually reboot to ensure a complete clean
It's normal after running TFC cleaner that the PC will be slower to boot the first time.
Tried both, same problems. Java simply disappears and MSE gives me an error message saying "An error has prevented the Microsoft Security Essentials Installation Wizard from continuing." Otherwise my computer is running fine now. Thank you again for all the help, Drew
Hi,

I'm not certain what could be causing this, lets run a couple more scans:

please rerun GMER and post the log

run this scan as well:


Download OTL to your Desktop
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Check the boxes beside LOP Check and Purity Check.
  • Under the Custom Scan box paste this in


    netsvcs
    %SYSTEMDRIVE%\*.exe
    /md5start
    eventlog.dll
    scecli.dll
    netlogon.dll
    cngaudit.dll
    sceclt.dll
    ntelogon.dll
    logevent.dll
    iaStor.sys
    nvstor.sys
    atapi.sys
    IdeChnDr.sys
    viasraid.sys
    AGP440.sys
    vaxscsi.sys
    nvatabus.sys
    viamraid.sys
    nvata.sys
    nvgts.sys
    iastorv.sys
    ViPrt.sys
    eNetHook.dll
    ahcix86.sys
    KR10N.sys
    nvstor32.sys
    ahcix86s.sys
    nvrd32.sys
    symmpi.sys
    adp3132.sys
    /md5stop
    %systemroot%\*. /mp /s
    %systemroot%\system32\*.dll /lockedfiles
    %systemroot%\Tasks\*.job /lockedfiles
    %systemroot%\system32\drivers\*.sys /lockedfiles
    %systemroot%\System32\config\*.sav
    CREATERESTOREPOINT

  • Click the Quick Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post them in your next reply.
Hi,

Sorry it took me a few days to do this. Here is the OTL.Txt log:

OTL logfile created on: 3/3/2010 7:12:05 AM - Run 1
OTL by OldTimer - Version 3.1.32.0 Folder = C:\Documents and Settings\Drew\Desktop
Windows XP Home Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 66.00% Memory free
3.00 Gb Paging File | 2.00 Gb Available in Paging File | 83.00% Paging File free
Paging file location(s): C:\pagefile.sys 0 0 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 33.01 Gb Total Space | 20.72 Gb Free Space | 62.76% Space Free | Partition Type: NTFS
Drive D: | 4.24 Gb Total Space | 0.56 Gb Free Space | 13.26% Space Free | Partition Type: FAT32
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: ANDREW-BDE706F3
Current User Name: Drew
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: On
Skip Microsoft Files: On
File Age = 14 Days
Output = Minimal
Quick Scan

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\Drew\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\OpenOffice.org 3\program\soffice.bin (OpenOffice.org)
PRC - C:\Program Files\OpenOffice.org 3\program\soffice.exe (OpenOffice.org)
PRC - C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
PRC - C:\Program Files\AIM6\aim6.exe (AOL LLC)
PRC - C:\Program Files\AIM6\aolsoftware.exe (AOL LLC)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe (Viewpoint Corporation)
PRC - C:\Program Files\Viewpoint\Common\ViewpointService.exe (Viewpoint Corporation)


========== Modules (SafeList) ==========

MOD - C:\Documents and Settings\Drew\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV - (WLSetupSvc) – C:\Program Files\Windows Live\installer\WLSetupSvc.exe (Microsoft Corporation)
SRV - (usnjsvc) – C:\Program Files\Windows Live\Messenger\usnsvc.exe (Microsoft Corporation)
SRV - (Viewpoint Manager Service) – C:\Program Files\Viewpoint\Common\ViewpointService.exe (Viewpoint Corporation)
SRV - (lxcc_device) – C:\WINDOWS\System32\lxcccoms.exe (Lexmark International, Inc.)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomSearch = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Google
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = http://www.google.com/search?q={searchTerm…tf8&oe=utf8
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = :0



O1 HOSTS File: ([2010/02/24 17:05:32 | 000,000,027 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (AcroIEHlprObj Class) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O4 - HKLM..\Run: [AlcxMonitor] C:\WINDOWS\ALCXMNTR.EXE (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [LXCCCATS] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXCCtime.DLL ()
O4 - HKLM..\Run: [QuickTime Task] C:\Program Files\QuickTime\qttask.exe (Apple Computer, Inc.)
O4 - HKCU..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk.disabled ()
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\NkvMon.exe.lnk.disabled ()
O4 - Startup: C:\Documents and Settings\Drew\Start Menu\Programs\Startup\OpenOffice.org 3.2.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O9 - Extra Button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll (Yahoo! Inc.)
O9 - Extra 'Tools' menuitem : Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll (Yahoo! Inc.)
O9 - Extra Button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe (America Online, Inc.)
O9 - Extra 'Tools' menuitem : Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://fpdownload.macromedia.com/get/shock…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos/OnlineScanner.cab (OnlineScanner Control)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.8.5.1302.1018.dll (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.8.5.1302.1018.dll (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\Drew\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Drew\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2005/07/10 15:17:28 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O32 - AutoRun File - [2001/07/28 07:07:38 | 000,000,000 | -HS- | M] () - D:\AUTOEXEC.BAT – [ FAT32 ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - comfile [open] – "%1" %*
O35 - exefile [open] – "%1" %*
O36 - AppCertDlls: eudcexnt - (C:\WINDOWS\dfrgtver.dll) - C:\WINDOWS\dfrgtver.dll File not found

NetSvcs: 6to4 - File not found
NetSvcs: Ias - C:\WINDOWS\system32\ias [2005/07/10 15:16:26 | 000,000,000 | —D | M]
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: Wmi - C:\WINDOWS\system32\wmi.dll (Microsoft Corporation)
NetSvcs: WmdmPmSp - File not found

CREATERESTOREPOINT
Restore point Set: OTL Restore Point (16610416650092544)

========== Files/Folders - Created Within 14 Days ==========

[2010/03/03 07:10:49 | 000,551,424 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Drew\Desktop\OTL.exe
[2010/02/27 12:55:37 | 000,000,000 | -HSD | C] – C:\RECYCLER
[2010/02/27 12:55:00 | 000,439,808 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Drew\Desktop\TFC.exe
[2010/02/27 11:07:25 | 000,000,000 | —D | C] – C:\WINDOWS\temp
[2010/02/27 11:00:59 | 000,031,232 | —- | C] (NirSoft) – C:\WINDOWS\NIRCMD.exe
[2010/02/27 10:51:41 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Windows Genuine Advantage
[2010/02/26 02:11:00 | 000,000,000 | —D | C] – C:\Documents and Settings\Drew\Local Settings\Application Data\Temp
[2010/02/25 18:40:58 | 000,000,000 | —D | C] – C:\_OTM
[2010/02/25 18:39:34 | 000,504,832 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Drew\Desktop\OTM.exe
[2010/02/25 16:46:22 | 000,000,000 | —D | C] – C:\Program Files\ESET
[2010/02/25 15:06:58 | 000,000,000 | —D | C] – C:\Documents and Settings\Drew\Application Data\Malwarebytes
[2010/02/25 15:06:54 | 000,038,224 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2010/02/25 15:06:52 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2010/02/25 15:06:51 | 000,019,160 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2010/02/25 15:06:51 | 000,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2010/02/25 15:06:19 | 005,115,824 | —- | C] (Malwarebytes Corporation ) – C:\Documents and Settings\Drew\Desktop\mbam-setup.exe
[2010/02/24 18:47:02 | 000,000,000 | —D | C] – C:\Documents and Settings\Drew\Desktop\Netdraft2full
[2010/02/24 18:30:39 | 000,000,000 | —D | C] – C:\Documents and Settings\Drew\My Documents\Netdraft 2
[2010/02/24 17:20:47 | 000,000,000 | —D | C] – C:\Documents and Settings\Drew\Desktop\tdsskiller
[2010/02/23 22:52:28 | 000,000,000 | —D | C] – C:\Program Files\mIRC
[2010/02/23 22:52:28 | 000,000,000 | —D | C] – C:\Documents and Settings\Drew\Application Data\mIRC
[2010/02/23 22:51:03 | 001,751,280 | —- | C] (mIRC Co. Ltd.) – C:\Documents and Settings\Drew\Desktop\mirc635.exe
[2010/02/23 18:12:03 | 000,000,000 | RHSD | C] – C:\cmdcons
[2010/02/23 18:03:34 | 000,212,480 | —- | C] (SteelWerX) – C:\WINDOWS\SWXCACLS.exe
[2010/02/23 18:03:34 | 000,161,792 | —- | C] (SteelWerX) – C:\WINDOWS\SWREG.exe
[2010/02/23 18:03:34 | 000,136,704 | —- | C] (SteelWerX) – C:\WINDOWS\SWSC.exe
[2010/02/23 17:30:38 | 000,000,000 | —D | C] – C:\WINDOWS\ERDNT
[2010/02/23 17:28:08 | 000,000,000 | —D | C] – C:\Qoobox
[2010/02/23 08:02:03 | 000,000,000 | —D | C] – C:\Program Files\MSECACHE
[2010/02/23 01:52:27 | 000,000,000 | —D | C] – C:\Documents and Settings\Drew\Desktop\spybot
[2010/02/23 01:50:48 | 000,000,000 | —D | C] – C:\Program Files\JRE
[2010/02/23 01:46:27 | 000,000,000 | —D | C] – C:\Config.Msi
[2010/02/23 01:28:25 | 000,000,000 | —D | C] – C:\Program Files\Eusing Free Registry Cleaner
[2010/02/21 19:45:03 | 000,000,000 | —D | C] – C:\Documents and Settings\Drew\Desktop\Resume
[2010/02/21 19:44:44 | 000,000,000 | —D | C] – C:\Documents and Settings\Drew\Desktop\Massage
[2010/02/21 19:43:05 | 000,000,000 | —D | C] – C:\Documents and Settings\Drew\Desktop\Mercer
[2010/01/28 17:11:01 | 000,000,000 | —D | M] – C:\Documents and Settings\NetworkService\Local Settings\Application Data\Google
[2010/01/28 17:06:10 | 000,000,000 | —D | M] – C:\Documents and Settings\LocalService\Local Settings\Application Data\Google
[2006/10/11 15:07:27 | 000,000,000 | –SD | M] – C:\Documents and Settings\LocalService\Application Data\Microsoft
[2005/07/10 15:23:02 | 000,000,000 | —D | M] – C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft
[2005/07/10 15:22:52 | 000,000,000 | –SD | M] – C:\Documents and Settings\NetworkService\Application Data\Microsoft
[2005/07/10 15:22:52 | 000,000,000 | —D | M] – C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft

========== Files - Modified Within 14 Days ==========

[2010/03/03 07:10:50 | 000,551,424 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Drew\Desktop\OTL.exe
[2010/03/03 06:17:00 | 000,000,886 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2010/03/03 02:17:00 | 000,000,882 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2010/03/02 22:43:47 | 001,488,886 | —- | M] () – C:\Documents and Settings\Drew\My Documents\IMG_0521.JPG
[2010/02/28 13:05:40 | 000,007,567 | —- | M] () – C:\Documents and Settings\Drew\Desktop\Joe.jpg
[2010/02/28 12:30:20 | 000,013,646 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2010/02/28 01:56:20 | 005,242,880 | -H– | M] () – C:\Documents and Settings\Drew\NTUSER.DAT
[2010/02/28 00:45:01 | 000,003,316 | —- | M] () – C:\Documents and Settings\Drew\Desktop\whatigotsofar.rtf
[2010/02/27 14:40:02 | 000,067,378 | —- | M] () – C:\Documents and Settings\Drew\My Documents\Photo 151.jpg
[2010/02/27 14:34:48 | 001,890,095 | —- | M] () – C:\Documents and Settings\Drew\My Documents\IMG_0503.JPG
[2010/02/27 14:33:46 | 001,991,493 | —- | M] () – C:\Documents and Settings\Drew\My Documents\IMG_0502.JPG
[2010/02/27 12:58:59 | 000,001,409 | —- | M] () – C:\WINDOWS\QTFont.for
[2010/02/27 12:58:58 | 000,054,156 | -H– | M] () – C:\WINDOWS\QTFont.qfn
[2010/02/27 12:57:07 | 000,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2010/02/27 12:57:03 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2010/02/27 12:57:01 | 1593,364,480 | -HS- | M] () – C:\hiberfil.sys
[2010/02/27 12:56:00 | 000,000,178 | -HS- | M] () – C:\Documents and Settings\Drew\ntuser.ini
[2010/02/27 12:55:05 | 000,439,808 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Drew\Desktop\TFC.exe
[2010/02/27 11:04:59 | 000,000,227 | —- | M] () – C:\WINDOWS\system.ini
[2010/02/27 10:59:25 | 003,874,353 | R— | M] () – C:\Documents and Settings\Drew\Desktop\ComboFixx.exe
[2010/02/27 03:40:32 | 000,020,172 | -H– | M] () – C:\WINDOWS\System32\mlfcache.dat
[2010/02/25 18:39:37 | 000,504,832 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Drew\Desktop\OTM.exe
[2010/02/25 15:38:11 | 000,001,917 | —- | M] () – C:\WINDOWS\imsins.BAK
[2010/02/25 15:06:56 | 000,000,696 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/02/25 15:06:23 | 005,115,824 | —- | M] (Malwarebytes Corporation ) – C:\Documents and Settings\Drew\Desktop\mbam-setup.exe
[2010/02/24 19:45:14 | 000,000,828 | —- | M] () – C:\Netdraft2Player-02252010-0045.dec
[2010/02/24 18:37:31 | 000,902,681 | —- | M] () – C:\Documents and Settings\Drew\Desktop\Netdraft2full.zip
[2010/02/24 18:36:43 | 000,601,277 | —- | M] () – C:\Documents and Settings\Drew\Desktop\netdraft2b_inst.exe
[2010/02/24 17:20:18 | 000,154,293 | —- | M] () – C:\Documents and Settings\Drew\Desktop\tdsskiller.zip
[2010/02/24 17:05:32 | 000,000,027 | —- | M] () – C:\WINDOWS\System32\drivers\etc\hosts
[2010/02/23 22:52:28 | 000,000,626 | —- | M] () – C:\Documents and Settings\All Users\Desktop\mIRC.lnk
[2010/02/23 22:51:04 | 001,751,280 | —- | M] (mIRC Co. Ltd.) – C:\Documents and Settings\Drew\Desktop\mirc635.exe
[2010/02/23 18:12:27 | 000,000,281 | RHS- | M] () – C:\boot.ini
[2010/02/23 14:14:21 | 000,284,915 | —- | M] () – C:\Documents and Settings\Drew\Desktop\gmer.zip
[2010/02/23 14:05:57 | 000,524,288 | —- | M] () – C:\Documents and Settings\Drew\Desktop\dds.com
[2010/02/23 07:30:36 | 004,831,316 | -H– | M] () – C:\Documents and Settings\Drew\Local Settings\Application Data\IconCache.db
[2010/02/23 01:28:27 | 000,000,740 | —- | M] () – C:\Documents and Settings\Drew\Desktop\Eusing Free Registry Cleaner.lnk
[2010/02/19 23:13:47 | 000,001,024 | —- | M] () – C:\WINDOWS\wininit.ini
[2010/02/19 19:31:06 | 000,126,112 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2010/02/19 02:22:37 | 000,091,020 | —- | M] () – C:\Documents and Settings\Drew\My Documents\Photo 161.jpg

========== Files Created - No Company Name ==========

[2010/03/02 22:43:22 | 001,488,886 | —- | C] () – C:\Documents and Settings\Drew\My Documents\IMG_0521.JPG
[2010/02/28 13:11:39 | 000,007,567 | —- | C] () – C:\Documents and Settings\Drew\Desktop\Joe.jpg
[2010/02/28 00:45:01 | 000,003,316 | —- | C] () – C:\Documents and Settings\Drew\Desktop\whatigotsofar.rtf
[2010/02/27 14:40:00 | 000,067,378 | —- | C] () – C:\Documents and Settings\Drew\My Documents\Photo 151.jpg
[2010/02/27 14:34:26 | 001,890,095 | —- | C] () – C:\Documents and Settings\Drew\My Documents\IMG_0503.JPG
[2010/02/27 14:33:22 | 001,991,493 | —- | C] () – C:\Documents and Settings\Drew\My Documents\IMG_0502.JPG
[2010/02/27 12:58:59 | 000,001,409 | —- | C] () – C:\WINDOWS\QTFont.for
[2010/02/27 12:58:58 | 000,054,156 | -H– | C] () – C:\WINDOWS\QTFont.qfn
[2010/02/27 10:59:23 | 003,874,353 | R— | C] () – C:\Documents and Settings\Drew\Desktop\ComboFixx.exe
[2010/02/27 03:40:32 | 000,020,172 | -H– | C] () – C:\WINDOWS\System32\mlfcache.dat
[2010/02/25 15:06:56 | 000,000,696 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/02/24 19:45:14 | 000,000,828 | —- | C] () – C:\Netdraft2Player-02252010-0045.dec
[2010/02/24 18:37:29 | 000,902,681 | —- | C] () – C:\Documents and Settings\Drew\Desktop\Netdraft2full.zip
[2010/02/24 18:36:39 | 000,601,277 | —- | C] () – C:\Documents and Settings\Drew\Desktop\netdraft2b_inst.exe
[2010/02/24 17:20:18 | 000,154,293 | —- | C] () – C:\Documents and Settings\Drew\Desktop\tdsskiller.zip
[2010/02/23 22:52:28 | 000,000,626 | —- | C] () – C:\Documents and Settings\All Users\Desktop\mIRC.lnk
[2010/02/23 18:12:26 | 000,000,211 | —- | C] () – C:\Boot.bak
[2010/02/23 18:12:17 | 000,260,272 | —- | C] () – C:\cmldr
[2010/02/23 18:03:34 | 000,261,632 | —- | C] () – C:\WINDOWS\PEV.exe
[2010/02/23 18:03:34 | 000,098,816 | —- | C] () – C:\WINDOWS\sed.exe
[2010/02/23 18:03:34 | 000,080,412 | —- | C] () – C:\WINDOWS\grep.exe
[2010/02/23 18:03:34 | 000,077,312 | —- | C] () – C:\WINDOWS\MBR.exe
[2010/02/23 18:03:34 | 000,068,096 | —- | C] () – C:\WINDOWS\zip.exe
[2010/02/23 14:17:59 | 000,293,376 | —- | C] () – C:\Documents and Settings\Drew\Desktop\gmer.exe
[2010/02/23 14:14:15 | 000,284,915 | —- | C] () – C:\Documents and Settings\Drew\Desktop\gmer.zip
[2010/02/23 14:05:54 | 000,524,288 | —- | C] () – C:\Documents and Settings\Drew\Desktop\dds.com
[2010/02/23 01:28:27 | 000,000,740 | —- | C] () – C:\Documents and Settings\Drew\Desktop\Eusing Free Registry Cleaner.lnk
[2010/02/19 23:13:36 | 000,001,024 | —- | C] () – C:\WINDOWS\wininit.ini
[2010/02/19 02:22:35 | 000,091,020 | —- | C] () – C:\Documents and Settings\Drew\My Documents\Photo 161.jpg
[2007/11/08 15:32:28 | 000,000,029 | —- | C] () – C:\WINDOWS\atid.ini
[2006/04/03 12:42:29 | 000,014,336 | —- | C] () – C:\Documents and Settings\Drew\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2005/10/02 14:55:51 | 000,000,754 | —- | C] () – C:\WINDOWS\WORDPAD.INI
[2005/09/16 14:56:24 | 000,032,768 | —- | C] () – C:\WINDOWS\System32\LXPRMON.DLL
[2005/09/16 14:56:24 | 000,020,480 | —- | C] () – C:\WINDOWS\System32\LXPMONUI.DLL
[2005/09/16 14:50:45 | 000,040,960 | —- | C] () – C:\WINDOWS\System32\lxccvs.dll
[2005/07/31 19:51:11 | 000,000,222 | —- | C] () – C:\WINDOWS\BLSnapshot.ini
[2005/07/16 18:02:31 | 000,001,558 | —- | C] () – C:\Documents and Settings\Drew\Application Data\AdobeDLM.log
[2005/07/16 18:02:31 | 000,000,000 | —- | C] () – C:\Documents and Settings\Drew\Application Data\dm.ini
[2004/09/17 16:37:42 | 000,061,440 | —- | C] () – C:\WINDOWS\System32\vuins32.dll

========== LOP Check ==========

[2010/02/05 13:55:03 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\acccore
[2010/02/05 13:55:06 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Viewpoint
[2010/02/05 13:57:04 | 000,000,000 | —D | M] – C:\Documents and Settings\Drew\Application Data\acccore
[2005/07/10 19:55:57 | 000,000,000 | —D | M] – C:\Documents and Settings\Drew\Application Data\Aim
[2005/08/30 20:25:50 | 000,000,000 | —D | M] – C:\Documents and Settings\Drew\Application Data\Nikon
[2010/02/14 17:09:55 | 000,000,000 | —D | M] – C:\Documents and Settings\Drew\Application Data\OpenOffice.org
[2007/01/11 11:16:49 | 000,000,000 | —D | M] – C:\Documents and Settings\Drew\Application Data\Viewpoint

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.exe >


< MD5 for: AGP440.SYS >
[2004/08/04 07:00:00 | 018,738,937 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\i386\sp2.cab:AGP440.sys
[2008/04/13 13:36:38 | 000,042,368 | —- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 – C:\WINDOWS\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\agp440.sys

< MD5 for: ATAPI.SYS >
[2004/08/04 07:00:00 | 018,738,937 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\i386\sp2.cab:atapi.sys
[2008/04/13 13:40:30 | 000,096,512 | —- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 – C:\WINDOWS\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\atapi.sys
[2004/08/04 07:00:00 | 000,095,360 | —- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 – C:\WINDOWS\ERDNT\cache\atapi.sys
[2004/08/04 07:00:00 | 000,095,360 | —- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 – C:\WINDOWS\system32\drivers\atapi.sys

< MD5 for: EVENTLOG.DLL >
[2008/04/13 19:11:53 | 000,056,320 | —- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 – C:\WINDOWS\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\eventlog.dll
[2004/08/04 07:00:00 | 000,055,808 | —- | M] (Microsoft Corporation) MD5=82B24CB70E5944E6E34662205A2A5B78 – C:\WINDOWS\ERDNT\cache\eventlog.dll
[2004/08/04 07:00:00 | 000,055,808 | —- | M] (Microsoft Corporation) MD5=82B24CB70E5944E6E34662205A2A5B78 – C:\WINDOWS\system32\dllcache\eventlog.dll
[2004/08/04 07:00:00 | 000,055,808 | —- | M] (Microsoft Corporation) MD5=82B24CB70E5944E6E34662205A2A5B78 – C:\WINDOWS\system32\eventlog.dll

< MD5 for: NETLOGON.DLL >
[2008/04/13 19:12:01 | 000,407,040 | —- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 – C:\WINDOWS\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\netlogon.dll
[2009/02/06 13:46:09 | 000,408,064 | —- | M] (Microsoft Corporation) MD5=6C476D33D82F1054849790181E8F7772 – C:\WINDOWS\$hf_mig$\KB968389\SP2QFE\netlogon.dll
[2009/02/06 13:46:09 | 000,408,064 | —- | M] (Microsoft Corporation) MD5=6C476D33D82F1054849790181E8F7772 – C:\WINDOWS\$hf_mig$\KB975467\SP2QFE\netlogon.dll
[2004/08/04 07:00:00 | 000,407,040 | —- | M] (Microsoft Corporation) MD5=96353FCECBA774BB8DA74A1C6507015A – C:\WINDOWS\ERDNT\cache\netlogon.dll
[2004/08/04 07:00:00 | 000,407,040 | —- | M] (Microsoft Corporation) MD5=96353FCECBA774BB8DA74A1C6507015A – C:\WINDOWS\system32\dllcache\netlogon.dll
[2004/08/04 07:00:00 | 000,407,040 | —- | M] (Microsoft Corporation) MD5=96353FCECBA774BB8DA74A1C6507015A – C:\WINDOWS\system32\netlogon.dll

< MD5 for: SCECLI.DLL >
[2004/08/04 07:00:00 | 000,180,224 | —- | M] (Microsoft Corporation) MD5=0F78E27F563F2AAF74B91A49E2ABF19A – C:\WINDOWS\ERDNT\cache\scecli.dll
[2004/08/04 07:00:00 | 000,180,224 | —- | M] (Microsoft Corporation) MD5=0F78E27F563F2AAF74B91A49E2ABF19A – C:\WINDOWS\system32\dllcache\scecli.dll
[2004/08/04 07:00:00 | 000,180,224 | —- | M] (Microsoft Corporation) MD5=0F78E27F563F2AAF74B91A49E2ABF19A – C:\WINDOWS\system32\scecli.dll
[2008/04/13 19:12:05 | 000,181,248 | —- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 – C:\WINDOWS\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\scecli.dll

< %systemroot%\*. /mp /s >

< %systemroot%\system32\*.dll /lockedfiles >
[2010/01/05 05:00:24 | 000,192,512 | —- | M] (Microsoft Corporation) Unable to obtain MD5 – C:\WINDOWS\system32\iepeers.dll

< %systemroot%\Tasks\*.job /lockedfiles >

< %systemroot%\system32\drivers\*.sys /lockedfiles >

< %systemroot%\System32\config\*.sav >
[2005/07/09 13:42:07 | 000,094,208 | —- | M] () – C:\WINDOWS\system32\config\default.sav
[2005/07/09 13:42:07 | 000,634,880 | —- | M] () – C:\WINDOWS\system32\config\software.sav
[2005/07/09 13:42:07 | 000,872,448 | —- | M] () – C:\WINDOWS\system32\config\system.sav
< End of report >



And Extras.Txt:


OTL Extras logfile created on: 3/3/2010 7:12:05 AM - Run 1
OTL by OldTimer - Version 3.1.32.0 Folder = C:\Documents and Settings\Drew\Desktop
Windows XP Home Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 66.00% Memory free
3.00 Gb Paging File | 2.00 Gb Available in Paging File | 83.00% Paging File free
Paging file location(s): C:\pagefile.sys 0 0 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 33.01 Gb Total Space | 20.72 Gb Free Space | 62.76% Space Free | Partition Type: NTFS
Drive D: | 4.24 Gb Total Space | 0.56 Gb Free Space | 13.26% Space Free | Partition Type: FAT32
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: ANDREW-BDE706F3
Current User Name: Drew
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: On
Skip Microsoft Files: On
File Age = 14 Days
Output = Minimal
Quick Scan

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
htmlfile – Reg Error: Key error.
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"139:TCP" = 139:TCP:LocalSubNet:Disabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Disabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Disabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Disabled:@xpsp2res.dll,-22002

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"C:\Program Files\AIM\aim.exe" = C:\Program Files\AIM\aim.exe:*:Enabled:AOL Instant Messenger – (America Online, Inc.)
"C:\Program Files\Windows Live\Messenger\livecall.exe" = C:\Program Files\Windows Live\Messenger\livecall.exe:*:Enabled:Windows Live Messenger (Phone) – (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\Yahoo!\Messenger\YServer.exe" = C:\Program Files\Yahoo!\Messenger\YServer.exe:*:Enabled:Yahoo! FT Server – (Yahoo! Inc.)
"C:\Program Files\Apprentice\Appr.exe" = C:\Program Files\Apprentice\Appr.exe:*:Enabled:Appr – ()
"C:\Program Files\AIM\aim.exe" = C:\Program Files\AIM\aim.exe:*:Enabled:AOL Instant Messenger – (America Online, Inc.)
"C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" = C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:*:Enabled:Yahoo! Messenger – (Yahoo! Inc.)
"C:\Program Files\Windows Live\Messenger\livecall.exe" = C:\Program Files\Windows Live\Messenger\livecall.exe:*:Enabled:Windows Live Messenger (Phone) – (Microsoft Corporation)
"C:\WINDOWS\system32\dpvsetup.exe" = C:\WINDOWS\system32\dpvsetup.exe:*:Enabled:Microsoft DirectPlay Voice Test – (Microsoft Corporation)
"C:\Program Files\Magic Workstation\MWSPlay.exe" = C:\Program Files\Magic Workstation\MWSPlay.exe:*:Enabled:Magic Workstation Play Module – (Magi-Soft Development)
"C:\Program Files\Common Files\AOL\Loader\aolload.exe" = C:\Program Files\Common Files\AOL\Loader\aolload.exe:*:Enabled:AOL Loader – (AOL LLC)
"C:\Program Files\AIM6\aim6.exe" = C:\Program Files\AIM6\aim6.exe:*:Enabled:AIM – (AOL LLC)
"C:\Program Files\NetDraft\NETDRAFT.EXE" = C:\Program Files\NetDraft\NETDRAFT.EXE:*:Enabled:NETDRAFT – ()
"C:\Program Files\mIRC\mirc.exe" = C:\Program Files\mIRC\mirc.exe:*:Enabled:mIRC – (mIRC Co. Ltd.)


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{508CE775-4BA4-4748-82DF-FE28DA9F03B0}" = Windows Live Messenger
"{6ADD0603-16EF-400D-9F9E-486432835002}" = OpenOffice.org 3.2
"{9422C8EA-B0C6-4197-B8FC-DC797658CA00}" = Windows Live Sign-in Assistant
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A7E4ECCA-4A8E-4258-8EC8-2DCCF5B11320}" = Windows Live installer
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AAB84E83-C8DF-4752-9DFC-2E2A48EE5E9F}" = Nikon View 6
"{AC76BA86-7AD7-1033-7B44-A70000000000}" = Adobe Reader 7.0
"{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C4124E95-5061-4776-8D5D-E3D931C778E1}" = Microsoft VC9 runtime libraries
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"AdobeESD" = Adobe Download Manager 2.0 (Remove Only)
"AIM_6" = AIM 6
"AOL Instant Messenger" = AOL Instant Messenger
"ComcastHSI" = Comcast High-Speed Internet Install Wizard
"ESET Online Scanner" = ESET Online Scanner v3
"Eusing Free Registry Cleaner" = Eusing Free Registry Cleaner
"HijackThis" = HijackThis 2.0.2
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"Lexmark 3300 Series" = Lexmark 3300 Series
"Lexmark Fax Solutions" = Lexmark Fax Solutions
"Macromedia Shockwave Player" = Macromedia Shockwave Player
"Magic Workstation_is1" = Magic Workstation 0.94f
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"mIRC" = mIRC
"MSNINST" = MSN
"MTG GamePack for Magic Workstation_is1" = MTG GamePack for Magic Workstation
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"QuickTime" = QuickTime
"S3Gamma2" = S3Gamma2
"S3Info2" = S3Info2
"S3Overlay" = S3Overlay
"Viewpoint Manager" = Viewpoint Manager (Remove Only)
"ViewpointMediaPlayer" = Viewpoint Media Player
"VN_VUIns_Rhine_VIA" = VIA Rhine-Family Fast Ethernet Adapter
"WIC" = Windows Imaging Component
"WinRAR archiver" = WinRAR archiver
"Yahoo! Messenger" = Yahoo! Messenger
"Yahoo! Messenger Explorer Bar" = Yahoo! Messenger Explorer Bar

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 2/5/2010 11:17:39 PM | Computer Name = ANDREW-BDE706F3 | Source = Application Error | ID = 1000
Description = Faulting application mwsplay.exe, version 0.9.4.440, faulting module
mwsplay.exe, version 0.9.4.440, fault address 0x0002ec6b.

Error - 2/6/2010 2:37:18 AM | Computer Name = ANDREW-BDE706F3 | Source = Application Error | ID = 1000
Description = Faulting application mwsplay.exe, version 0.9.4.440, faulting module
kernel32.dll, version 5.1.2600.3541, fault address 0x00012a6b.

Error - 2/6/2010 2:44:40 PM | Computer Name = ANDREW-BDE706F3 | Source = Application Error | ID = 1000
Description = Faulting application mwsplay.exe, version 0.9.4.440, faulting module
unknown, version 0.0.0.0, fault address 0x013991aa.

Error - 2/8/2010 3:20:41 PM | Computer Name = ANDREW-BDE706F3 | Source = Application Hang | ID = 1002
Description = Hanging application SpybotSD.exe, version 1.5.2.20, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.

Error - 2/8/2010 3:47:36 PM | Computer Name = ANDREW-BDE706F3 | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 7.0.6000.16981, faulting
module ntdll.dll, version 5.1.2600.3520, fault address 0x00018af2.

Error - 2/8/2010 3:47:52 PM | Computer Name = ANDREW-BDE706F3 | Source = Application Hang | ID = 1002
Description = Hanging application iexplore.exe, version 7.0.6000.16981, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 2/10/2010 12:56:00 AM | Computer Name = ANDREW-BDE706F3 | Source = Application Hang | ID = 1002
Description = Hanging application TeaTimer.exe, version 1.5.2.16, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.

Error - 2/10/2010 5:40:44 PM | Computer Name = ANDREW-BDE706F3 | Source = Application Hang | ID = 1002
Description = Hanging application iexplore.exe, version 7.0.6000.16981, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 2/12/2010 1:25:00 PM | Computer Name = ANDREW-BDE706F3 | Source = crypt32 | ID = 131083
Description = Failed extract of third-party root list from auto update cab at: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>
with error: A required certificate is not within its validity period when verifying
against the current system clock or the timestamp in the signed file.

Error - 2/12/2010 5:47:22 PM | Computer Name = ANDREW-BDE706F3 | Source = Application Hang | ID = 1002
Description = Hanging application iexplore.exe, version 7.0.6000.16981, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

[ System Events ]
Error - 2/24/2010 7:11:28 PM | Computer Name = ANDREW-BDE706F3 | Source = Service Control Manager | ID = 7023
Description = The Application Management service terminated with the following error:
%%126

Error - 2/24/2010 7:11:28 PM | Computer Name = ANDREW-BDE706F3 | Source = Service Control Manager | ID = 7023
Description = The Application Management service terminated with the following error:
%%126

Error - 2/24/2010 7:11:28 PM | Computer Name = ANDREW-BDE706F3 | Source = Service Control Manager | ID = 7023
Description = The Application Management service terminated with the following error:
%%126

Error - 2/24/2010 7:11:28 PM | Computer Name = ANDREW-BDE706F3 | Source = Service Control Manager | ID = 7023
Description = The Application Management service terminated with the following error:
%%126

Error - 2/24/2010 7:11:28 PM | Computer Name = ANDREW-BDE706F3 | Source = Service Control Manager | ID = 7023
Description = The Application Management service terminated with the following error:
%%126

Error - 2/24/2010 7:11:28 PM | Computer Name = ANDREW-BDE706F3 | Source = Service Control Manager | ID = 7023
Description = The Application Management service terminated with the following error:
%%126

Error - 2/24/2010 7:11:28 PM | Computer Name = ANDREW-BDE706F3 | Source = Service Control Manager | ID = 7023
Description = The Application Management service terminated with the following error:
%%126

Error - 2/24/2010 7:11:28 PM | Computer Name = ANDREW-BDE706F3 | Source = Service Control Manager | ID = 7023
Description = The Application Management service terminated with the following error:
%%126

Error - 2/25/2010 7:41:00 PM | Computer Name = ANDREW-BDE706F3 | Source = Service Control Manager | ID = 7034
Description = The Viewpoint Manager Service service terminated unexpectedly. It
has done this 1 time(s).

Error - 2/27/2010 1:55:09 PM | Computer Name = ANDREW-BDE706F3 | Source = Service Control Manager | ID = 7034
Description = The Viewpoint Manager Service service terminated unexpectedly. It
has done this 1 time(s).


< End of report >




Thank you again,
Drew
Hi,

Please do the following:

Run OTL.exe
  • Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :OTL
    O36 - AppCertDlls: eudcexnt - (C:\WINDOWS\dfrgtver.dll) - C:\WINDOWS\dfrgtver.dll File not found
    
    :Commands
    [purity]
    [emptytemp]
    [Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
  • Then post the OTL log

There doesn't appear to be anything in the log that would indicate why Java and MSE wont install.

The only thing might be teatimer interfering.

Makesure teatimer is totally disabled or uninstall it till you are done.

Were you able to run the GMER scan?
OTL log: All processes killed ========== OTL ========== Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\AppCertDlls\\eudcexnt:C:\WINDOWS\dfrgtver.dll deleted successfully. ========== COMMANDS ========== [EMPTYTEMP] User: All Users User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: Drew ->Temp folder emptied: 239478 bytes ->Temporary Internet Files folder emptied: 983899491 bytes ->Flash cache emptied: 6458 bytes User: Guest ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes ->Flash cache emptied: 2822 bytes User: LocalService ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 33385 bytes User: NetworkService ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 33170 bytes %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 0 bytes %systemroot%\System32 .tmp files removed: 0 bytes %systemroot%\System32\dllcache .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 480 bytes %systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes %systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 0 bytes RecycleBin emptied: 0 bytes Total Files Cleaned = 939.00 mb OTL by OldTimer - Version 3.1.32.0 log created on 03032010_083023 Files\Folders moved on Reboot… File\Folder C:\Documents and Settings\Drew\Local Settings\Temp\svj6f.tmp\svj7k.tmp not found! Registry entries deleted on Reboot… I was able to run the Gmer scan ten days ago, should I run it again and post the new log? Thank you, Drew
Tried installing Java again, "downloading installer" box came up again, disappeared, got a message saying "Abort Java Download: To restart download refresh webpage." Running gmer scan now…

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI