This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Popups and Reboots

14 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

This PC is experiencing popup windows while web browsing (in the form of opening a new tab - using Firefox). Usually occurs when clicking a valid link, but it goes elsewhere. Very annoying.
This PC is also experiencing reboots which might not be related, but I am not discounting anything at this point.
I figure, if we can clean the system of this popup problem, we can see what we have left.

DDS.TXT follows:

DDS (Ver_09-06-26.01) - NTFSx86
Run by [removed] at 14:14:30.04 on Wed 03/31/2010
Internet Explorer: 8.0.6001.18702
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1022.534 [GMT -4:00]

AV: AntiVir Desktop *On-access scanning disabled* (Outdated) {AD166499-45F9-482A-A743-FDD3350758C7}

============== Running Processes ===============

C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
C:\WINDOWS\Explorer.EXE
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir Desktop\sched.exe
svchost.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Avira\AntiVir Desktop\avguard.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Avira\AntiVir Desktop\avshadow.exe
C:\Program Files\Nero\Nero8\InCD\InCDsrv.exe
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
svchost.exe
C:\WINDOWS\system32\dllhost.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\explorer.exe
C:\Users\Administrator\Desktop\dds.scr

============== Pseudo HJT Report ===============

mDefault_Page_URL = hxxp://www.yahoo.com
mStart Page = hxxp://www.yahoo.com
mWinlogon: UIHost=%SystemRoot%\System32\ultlogonui.exe
BHO: {02478D38-C3F9-4efb-9B51-7695ECA05670} - No File
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Search Helper: {6ebf7485-159f-4bff-a14f-b9e3aac4465b} - c:\program files\microsoft\search enhancement pack\search helper\SearchHelper.dll
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Windows Live Toolbar Helper: {e15a8dc0-8516-42a1-81ea-dc94ec1acf10} - c:\program files\windows live\toolbar\wltcore.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: QT TabBar: {d2bf470e-ed1c-487f-a333-2bd8835eb6ce} - mscoree.dll
TB: QT Tab Standard Buttons: {d2bf470e-ed1c-487f-a666-2bd8835eb6ce} - mscoree.dll
TB: QT Breadcrumbs Address Bar: {af83e43c-dd2b-4787-826b-31b17dee52ed} - mscoree.dll
TB: &Windows Live Toolbar: {21fa44ef-376d-4d53-9b0f-8a89d3229068} - c:\program files\windows live\toolbar\wltcore.dll
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
mRun: [nwiz] nwiz.exe /installquiet
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit
mRun: [avgnt] "c:\program files\avira\antivir desktop\avgnt.exe" /min
dRun: [MsnMsgr] "c:\program files\windows live\messenger\msnmsgr.exe" /background
dRunOnce: [_nltide_2] regsvr32 /s /n /i:U shell32
uPolicies-explorer: NoRecentDocsNetHood = 1 (0x1)
mPolicies-explorer: NoRecentDocsNetHood = 1 (0x1)
dPolicies-explorer: NoRecentDocsNetHood = 1 (0x1)
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab
Notify: igfxcui - igfxsrvc.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\wpdshserviceobj.dll

================= FIREFOX ===================

FF - ProfilePath - c:\users\admini~1\applic~1\mozilla\firefox\profiles\uvyx04g7.default\
FF - plugin: c:\program files\windows live\photo gallery\NPWLPG.dll

—- FIREFOX POLICIES —-
c:\program files\mozilla firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.enforce_same_site_origin", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.cache_size", 51200);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.ogg.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.wave.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.autoplay.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.urlbar.autocomplete.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("capability.policy.mailnews.*.wholeText", "noAccess");
c:\program files\mozilla firefox\greprefs\all.js - pref("dom.storage.default_quota", 5120);
c:\program files\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32);
c:\program files\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.http.prompt-temp-redirect", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("layout.css.dpi", -1);
c:\program files\mozilla firefox\greprefs\all.js - pref("layout.css.devPixelsPerPx", "-1");
c:\program files\mozilla firefox\greprefs\all.js - pref("gestures.enable_single_finger_input", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.debug", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.tcp.sendbuffer", 131072);
c:\program files\mozilla firefox\greprefs\all.js - pref("geo.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("html5.enable", false);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pr
ef", true);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.remember_cert_checkbox_default_setting", true);
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600);
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com");
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr", "moz35");
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-cjkt", "moz35"); // now unused
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.blocklist.level", 2);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.delay", 50);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.restrict.typed", "~");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.default.behavior", 0);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.history", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.formdata", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.passwords", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.downloads", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cookies", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cache", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.sessions", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.offlineApps", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.siteSettings", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.history", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.formdata", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.passwords", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.downloads", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.cookies", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.cache", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.sessions", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.offlineApps", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.siteSettings", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.sanitize.migrateFx3Prefs", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.ssl_override_behavior", 2);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("security.alternate_certificate_error_page", "certerror");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.autostart", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.dont_prompt_on_enter", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("geo.wifi.uri", "https://www.google.com/loc/json");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20);

============= SERVICES / DRIVERS ===============

R1 avgio;avgio;c:\program files\avira\antivir desktop\avgio.sys [2010-3-24 11608]
R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\avira\antivir desktop\sched.exe [2010-3-24 135336]
R2 AntiVirService;Avira AntiVir Guard;c:\program files\avira\antivir desktop\avguard.exe [2010-3-24 267432]
R2 avgntflt;avgntflt;c:\windows\system32\drivers\avgntflt.sys [2010-2-26 60936]
R2 fssfltr;FssFltr;c:\windows\system32\drivers\fssfltr_tdi.sys [2010-2-20 54752]
R2 SeaPort;SeaPort;c:\program files\microsoft\search enhancement pack\seaport\SeaPort.exe [2009-1-14 226656]
S3 fsssvc;Windows Live Family Safety Service;c:\program files\windows live\family safety\fsssvc.exe [2009-8-5 704864]
S3 McrdSvc;Media Center Extender Service;c:\windows\ehome\mcrdsvc.exe [2005-8-5 99328]
S4 NeroRegInCDSrv;Nero Registry InCD Service;c:\program files\nero\nero8\incd\NBHRegInCDSrv.exe [2008-6-10 53032]

=============== Created Last 30 ================

2010-03-26 18:21 552 a——- c:\windows\system32\d3d8caps.dat
2010-03-25 17:16 –d—– c:\users\admini~1\applic~1\GARMIN
2010-03-25 17:15 –d—– c:\program files\Garmin GPS Plugin
2010-03-25 17:15 –d—– c:\program files\Garmin
2010-03-24 22:26 38,224 a——- c:\windows\system32\drivers\mbamswissarmy.sys
2010-03-24 22:26 19,160 a——- c:\windows\system32\drivers\mbam.sys
2010-03-24 22:26 –d—– c:\program files\Malwarebytes' Anti-Malware
2010-03-24 21:42 –d—– c:\users\admini~1\applic~1\Avira
2010-03-24 20:30 –d—– c:\users\alluse~1\applic~1\Avira
2010-03-24 20:30 –d—– c:\program files\Avira
2010-03-20 20:17 69 a——- c:\windows\NeroDigital.ini
2010-03-20 19:28 377,344 a–sh— C:\ehthumbs.db
2010-03-17 20:00 –d—– c:\program files\VS Revo Group
2010-03-17 18:19 –d—– c:\windows\system32\appmgmt
2010-03-12 13:19 96,512 a——- c:\windows\system32\drivers\SET8.tmp
2010-03-08 02:07 –d—– c:\users\administrator\MySpaceIM Pics
2010-03-08 02:05 –d—– c:\users\admini~1\applic~1\MySpace
2010-03-08 02:05 –d—– c:\program files\MySpace
2010-03-08 00:57 754 a——- c:\windows\WORDPAD.INI
2010-03-07 19:52 96,512 a——- c:\windows\system32\drivers\SET4.tmp

==================== Find3M ====================

2010-03-29 21:30 96,512 a——- c:\windows\system32\drivers\atapi.sys
2010-02-16 13:24 60,936 a——- c:\windows\system32\drivers\avgntflt.sys
2010-02-08 22:56 1,536 a——- c:\windows\system32\TrueSoft.dat
2010-02-08 20:58 86,811 a——- c:\windows\pchealth\helpctr\offlinecache\index.dat
2010-02-08 20:32 411,368 a——- c:\windows\system32\deploytk.dll
2010-02-08 20:10 21,640 a——- c:\windows\system32\emptyregdb.dat
2010-01-12 00:03 14,458,880 a——- c:\windows\system32\nvoglnt.dll
2010-01-12 00:03 11,632,640 a——- c:\windows\system32\nvcompiler.dll
2010-01-12 00:03 6,359,168 a——- c:\windows\system32\nv4_disp.dll
2010-01-12 00:03 4,104,192 a——- c:\windows\system32\nvcuda.dll
2010-01-12 00:03 4,077,672 a——- c:\windows\system32\nvcuvenc.dll
2010-01-12 00:03 2,283,526 a——- c:\windows\system32\nvdata.bin
2010-01-12 00:03 2,259,560 a——- c:\windows\system32\nvcuvid.dll
2010-01-12 00:03 1,081,344 a——- c:\windows\system32\nvapi.dll
2010-01-12 00:03 592,488 a——- c:\windows\system32\nvudisp.exe
2010-01-12 00:03 182,888 a——- c:\windows\system32\nvcodins.dll
2010-01-12 00:03 182,888 a——- c:\windows\system32\nvcod.dll
2010-01-12 00:03 61,440 a——- c:\windows\system32\OpenCL.dll
2010-01-11 23:17 13,666,408 a——- c:\windows\system32\nvcpl.dll
2010-01-11 23:17 278,120 a——- c:\windows\system32\nvmccs.dll
2010-01-11 23:17 154,216 a——- c:\windows\system32\nvsvc32.exe
2010-01-11 23:17 145,000 a——- c:\windows\system32\nvcolor.exe
2010-01-11 23:17 110,696 a——- c:\windows\system32\nvmctray.dll
2010-01-11 23:17 81,920 a——- c:\windows\system32\nvwddi.dll
2008-01-21 23:51 121 a—h— c:\program files\desktop.ini

============= FINISH: 14:15:51.62 ===============


GMER.TXT follows:
GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-03-31 14:54:04
Windows 5.1.2600 Service Pack 3
Running: eclzvb7p.exe; Driver: C:\Users\ADMINI~1\LOCALS~1\Temp\axworaoc.sys


—- System - GMER 1.0.15 —-

SSDT F212AEC6 ZwCreateKey
SSDT F212AEBC ZwCreateThread
SSDT F212AECB ZwDeleteKey
SSDT F212AED5 ZwDeleteValueKey
SSDT F212AEDA ZwLoadKey
SSDT F212AEA8 ZwOpenProcess
SSDT F212AEAD ZwOpenThread
SSDT F212AEE4 ZwReplaceKey
SSDT F212AEDF ZwRestoreKey
SSDT F212AED0 ZwSetValueKey

—- Devices - GMER 1.0.15 —-

AttachedDevice \FileSystem\Ntfs \Ntfs InCDRec.sys (Nero InCD File System Recognizer/Nero AG)
AttachedDevice \Driver\Tcpip \Device\Tcp fssfltr_tdi.sys (Family Safety Filter Driver (TDI)/Microsoft Corporation)

Device mrxsmb.sys (Windows NT SMB Minirdr/Microsoft Corporation)
Device Fastfat.SYS (Fast FAT File System Driver/Microsoft Corporation)

AttachedDevice fltMgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)

Device Fs_Rec.SYS (File System Recognizer Driver/Microsoft Corporation)
Device InCDFs.sys (InCD File System Driver/Nero AG)
Device -> \Driver\atapi \Device\Harddisk0\DR0 86706B4C

—- Files - GMER 1.0.15 —-

File C:\WINDOWS\system32\drivers\atapi.sys suspicious modification

—- EOF - GMER 1.0.15 —-


Attach.txt is attached

Attachments:

Hello Trilo and welcome to WhatTheTech. I’ll be happy to look over your log and help you with your issues. It will be very helpful if you follow these guidelines:
  • Malware removal is a sometimes lengthy and tedious process. Please stick with the thread until I’ve given you the “All clear.” Absence of symptoms does not mean your machine is clean!
  • Please do not run any scans or install/uninstall any applications without being directed to do so.
  • Please follow my instructions carefully and in the order they are posted.
  • Any underlined text in my posts indicates a clickable link.
  • You should print any instructions I give you for ease of use and reference.
  • If you have any questions at all, please stop and ask before proceeding.
Please be advised, as I am still in training, all my replies to you will be checked for accuracy by one of our experts to ensure that I am giving you the best possible advise.This may cause a delay, but I will do my best to keep it as short as possible.

I will post back as soon as possible with instructions.
Trilo,

🖼Click to load external image (Posted Image) You are infected with a rootkit. Rootkits and Backdoor Trojans are very dangerous because they can bypass security mechanisms and steal sensitive information which they send back to the hacker. All passwords should be changed immediately using a different computer.

🖼Click to load external image (Posted Image) Download ComboFix from one of the following locations:
Link 1
Link 2

VERY IMPORTANT !!! Save ComboFix.exe to your Desktop

* IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
  • Double click on ComboFix.exe & follow the prompts.
As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]

  • Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]

  • Click on Yes, to continue scanning for malware.
When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.
Notes:
1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.


Please include the following in your next post:
  • ComboFix log
  • How is the computer running?
The computer rebooted very quickly. nice.
Web browsing is the way it should be now. No more random popups.
:thumbup:
Not sure yet about the rebooting problem, but as I said before, we are actually treating that as a separate problem to keep an eye out for, but so far … so good.

Thank you.

ComboFix.txt follows:
ComboFix 10-03-29.04 - Administrator 04/01/2010 12:06:39.1.1 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1022.681 [GMT -4:00]
Running from: c:\users\[removed]\Desktop\ComboFix.exe
AV: AntiVir Desktop *On-access scanning disabled* (Outdated) {AD166499-45F9-482A-A743-FDD3350758C7}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

Infected copy of c:\windows\system32\DRIVERS\atapi.sys was found and disinfected
Restored copy from - Kitty ate it :P
.
((((((((((((((((((((((((( Files Created from 2010-03-01 to 2010-04-01 )))))))))))))))))))))))))))))))
.

2010-03-31 18:09 . 2010-03-31 18:09 ——– d—–w- c:\program files\ERUNT
2010-03-26 22:21 . 2010-03-26 22:21 552 —-a-w- c:\windows\system32\d3d8caps.dat
2010-03-25 21:16 . 2010-03-25 21:16 ——– d—–w- c:\users\Administrator\Application Data\GARMIN
2010-03-25 21:15 . 2010-03-25 21:15 ——– d—–w- c:\program files\Garmin GPS Plugin
2010-03-25 21:15 . 2010-03-25 21:15 ——– d—–w- c:\program files\DIFX
2010-03-25 21:15 . 2010-03-25 21:15 ——– d—–w- c:\program files\Garmin
2010-03-25 02:26 . 2010-01-07 20:07 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-03-25 02:26 . 2010-03-25 02:26 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2010-03-25 02:26 . 2010-01-07 20:07 19160 —-a-w- c:\windows\system32\drivers\mbam.sys
2010-03-25 01:42 . 2010-03-25 01:42 ——– d—–w- c:\users\Administrator\Application Data\Avira
2010-03-25 00:30 . 2010-03-01 13:05 124784 —-a-w- c:\windows\system32\drivers\avipbb.sys
2010-03-25 00:30 . 2009-05-11 15:49 45416 —-a-w- c:\windows\system32\drivers\avgntdd.sys
2010-03-25 00:30 . 2009-05-11 15:49 22360 —-a-w- c:\windows\system32\drivers\avgntmgr.sys
2010-03-25 00:30 . 2010-03-25 00:30 ——– d—–w- c:\users\All Users\Application Data\Avira
2010-03-25 00:30 . 2010-03-25 00:30 ——– d—–w- c:\program files\Avira
2010-03-20 23:19 . 2010-03-20 23:19 0 —-a-w- c:\windows\nsreg.dat
2010-03-18 00:00 . 2010-03-18 00:00 ——– d—–w- c:\program files\VS Revo Group
2010-03-17 23:09 . 2010-03-18 00:03 ——– d—–w- c:\program files\Windows Live
2010-03-17 23:08 . 2010-03-17 23:08 ——– d—–w- c:\program files\Microsoft Sync Framework
2010-03-13 15:57 . 2010-03-13 15:57 ——– d—–w- c:\users\Administrator\Local Settings\Application Data\Symantec
2010-03-08 06:07 . 2010-03-08 06:07 ——– d—–w- c:\users\Administrator\MySpaceIM Pics
2010-03-08 06:07 . 2010-03-08 06:07 ——– d—–w- c:\users\\Administrator\MySpaceIM Pics
2010-03-08 06:05 . 2010-03-08 06:06 ——– d—–w- c:\users\Administrator\Application Data\MySpace
2010-03-08 06:05 . 2010-03-13 16:03 ——– d—–w- c:\program files\MySpace
2010-03-08 06:04 . 2010-03-08 06:04 7631232 —-a-w- c:\users\Administrator\Application Data\MySpace\IM\Install\MSIMClientSetup.1.0.823.0-static-A.exe
2010-03-05 22:54 . 2010-03-05 22:54 ——– d—–w- c:\users\All Users\Application Data\McAfee
2010-03-05 00:15 . 2010-03-05 00:15 ——– d—–w- c:\users\Administrator\Local Settings\Application Data\Identities

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-04-01 15:43 . 2010-02-12 17:27 1 —-a-w- c:\users\Administrator\Application Data\OpenOffice.org\3\user\uno_packages\cache\stamp.sys
2010-04-01 01:13 . 2008-04-14 12:00 96512 —-a-w- c:\windows\system32\drivers\atapi.sys
2010-03-31 00:35 . 2010-02-26 06:56 664 —-a-w- c:\windows\system32\d3d9caps.dat
2010-03-25 00:23 . 2010-02-12 15:57 ——– d—–w- c:\users\All Users\Application Data\Norton
2010-03-24 21:27 . 2010-02-09 02:51 ——– d–h–w- c:\program files\InstallShield Installation Information
2010-03-24 21:26 . 2010-02-09 02:51 ——– d—–w- c:\program files\Common Files\InstallShield
2010-03-17 22:30 . 2010-02-22 21:20 ——– d—–w- c:\program files\Google
2010-03-12 11:33 . 2010-02-13 02:09 ——– d—–w- c:\users\All Users\Application Data\Yahoo!
2010-03-12 11:32 . 2010-02-13 02:09 ——– d—–w- c:\users\Administrator\Application Data\Yahoo!
2010-02-27 19:17 . 2010-02-27 19:17 ——– d—–w- c:\users\Administrator\Application Data\Malwarebytes
2010-02-27 19:16 . 2010-02-27 19:16 ——– d—–w- c:\users\All Users\Application Data\Malwarebytes
2010-02-21 02:39 . 2010-02-21 02:39 ——– d—–w- c:\program files\Microsoft Silverlight
2010-02-21 02:35 . 2010-02-21 02:35 ——– d—–w- c:\program files\Microsoft
2010-02-21 02:32 . 2010-02-21 02:32 ——– d—–w- c:\program files\Common Files\Windows Live
2010-02-18 22:49 . 2010-02-18 22:49 ——– d—–w- c:\users\Administrator\Application Data\Turbine
2010-02-18 22:49 . 2010-02-18 22:49 119 —-a-w- c:\users\Administrator\Local Settings\Application Data\fusioncache.dat
2010-02-18 21:09 . 2010-02-18 21:09 ——– d—–w- c:\program files\Turbine
2010-02-17 05:11 . 2010-02-17 05:11 ——– d—–w- c:\program files\dx2
2010-02-17 02:43 . 2010-02-17 02:42 ——– d—–w- c:\program files\DX
2010-02-16 17:24 . 2010-02-26 17:58 60936 —-a-w- c:\windows\system32\drivers\avgntflt.sys
2010-02-14 05:47 . 2010-02-14 05:46 ——– d—–w- c:\program files\NVIDIA Corporation
2010-02-14 05:47 . 2010-02-14 05:47 ——– d—–w- c:\users\All Users\Application Data\NVIDIA Corporation
2010-02-14 00:05 . 2010-02-14 00:05 ——– d—–w- c:\program files\AGEIA Technologies
2010-02-14 00:05 . 2010-02-14 00:05 ——– d—–w- c:\program files\Common Files\Wise Installation Wizard
2010-02-13 04:43 . 2010-02-09 01:04 20536 —-a-w- c:\users\Administrator\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-02-13 03:44 . 2010-02-13 03:44 ——– d—–w- c:\users\All Users\Application Data\Symantec
2010-02-13 01:02 . 2010-02-13 00:43 ——– d—–w- c:\program files\Sony
2010-02-13 00:41 . 2010-02-13 00:41 ——– d—–w- c:\program files\Common Files\SWF Studio
2010-02-12 17:26 . 2010-02-12 17:26 ——– d—–w- c:\users\Administrator\Application Data\OpenOffice.org
2010-02-12 17:13 . 2010-02-12 17:13 ——– d—–w- c:\program files\JRE
2010-02-12 17:13 . 2010-02-12 17:13 ——– d—–w- c:\program files\OpenOffice.org 3
2010-02-12 15:57 . 2010-02-12 15:57 ——– d—–w- c:\users\All Users\Application Data\NortonInstaller
2010-02-09 02:56 . 2010-02-09 02:56 1536 —-a-w- c:\windows\system32\TrueSoft.dat
2010-02-09 02:56 . 2010-02-09 02:56 0 —-a-w- c:\windows\system32\PTPTT.dat
2010-02-09 02:56 . 2010-02-09 02:56 0 —-a-w- c:\windows\system32\PTHSP.dat
2010-02-09 01:16 . 2010-02-09 00:58 ——– d—–w- c:\program files\AVG
2010-02-09 00:58 . 2010-02-09 00:13 86811 —-a-w- c:\windows\pchealth\helpctr\OfflineCache\index.dat
2010-02-09 00:51 . 2010-02-09 00:51 ——– d—–w- c:\users\All Users\Application Data\Nero
2010-02-09 00:42 . 2010-02-09 00:42 ——– d—–w- c:\program files\microsoft frontpage
2010-02-09 00:42 . 2010-02-09 00:48 ——– d—a-w- c:\users\Administrator\Application Data\OtakuSoftware
2010-02-09 00:42 . 2010-02-09 00:42 ——– d—a-w- c:\users\Default User\Application Data\OtakuSoftware
2010-02-09 00:42 . 2010-02-09 00:48 ——– d—a-w- c:\users\Administrator\Application Data\Nero
2010-02-09 00:42 . 2010-02-09 00:42 ——– d—a-w- c:\users\Default User\Application Data\Nero
2010-02-09 00:34 . 2010-02-09 00:34 ——– d—–w- c:\program files\Common Files\Adobe
2010-02-09 00:33 . 2010-02-09 00:33 ——– d—–w- c:\program files\TUGZip
2010-02-09 00:32 . 2010-02-09 00:32 411368 —-a-w- c:\windows\system32\deploytk.dll
2010-02-09 00:31 . 2010-02-09 00:31 ——– d—–w- c:\program files\Java
2010-02-09 00:30 . 2010-02-09 00:30 ——– d—–w- c:\program files\MSBuild
2010-02-09 00:30 . 2010-02-09 00:30 ——– d—–w- c:\program files\Reference Assemblies
2010-02-09 00:26 . 2010-02-09 00:25 ——– d—–w- c:\program files\ffdshow
2010-02-09 00:16 . 2010-02-09 00:16 ——– d—–w- c:\program files\Microsoft SQL Server Compact Edition
2010-02-09 00:14 . 2010-02-09 00:14 ——– d—–w- c:\program files\MSXML 4.0
2010-02-09 00:10 . 2010-02-09 00:10 21640 —-a-w- c:\windows\system32\emptyregdb.dat
2010-02-09 00:10 . 2010-02-09 00:10 ——– d—–w- c:\program files\Windows Media Connect 2
2010-01-12 03:17 . 2010-01-12 03:17 278120 —-a-w- c:\windows\system32\nvmccs.dll
2010-01-12 03:17 . 2010-01-12 03:17 154216 —-a-w- c:\windows\system32\nvsvc32.exe
2010-01-12 03:17 . 2010-01-12 03:17 145000 —-a-w- c:\windows\system32\nvcolor.exe
2010-01-12 03:17 . 2010-01-12 03:17 13666408 —-a-w- c:\windows\system32\nvcpl.dll
2010-01-12 03:17 . 2010-01-12 03:17 110696 —-a-w- c:\windows\system32\nvmctray.dll
2010-01-12 03:17 . 2010-01-12 03:17 81920 —-a-w- c:\windows\system32\nvwddi.dll
.

——- Sigcheck ——-

[-] 2009-08-28 . F470A27484E43DA058BDFC235CD67FD1 . 361600 . . [5.1.2600.9999] . . c:\windows\system32\drivers\tcpip.sys
[-] 2009-08-28 . F470A27484E43DA058BDFC235CD67FD1 . 361600 . . [5.1.2600.9999] . . c:\windows\system32\syscache\tcpip.sys

[-] 2009-10-17 . C9FB1A9B3F9B51F08B665542DDFEE295 . 692736 . . [5.82] . . c:\windows\system32\comctl32.dll

[-] 2009-10-17 . 6616894470538493B9AAE74271F099EF . 578048 . . [5.1.2600.5512] . . c:\windows\system32\user32.dll

[-] 2009-10-17 . AEA58E2C358B987FCC612907377373C3 . 1697280 . . [6.00.2900.5512] . . c:\windows\explorer.exe

[-] 2009-10-17 . 362BC5AF8EAF712832C58CC13AE05750 . 1614848 . . [5.1.2600.5512] . . c:\windows\system32\sfcfiles.dll

[-] 2009-09-11 . EE87B66DBB4D5C44E94854118664EF42 . 295424 . . [5.1.2600.9999] . . c:\windows\system32\termsrv.dll
[-] 2009-09-11 . EE87B66DBB4D5C44E94854118664EF42 . 295424 . . [5.1.2600.9999] . . c:\windows\system32\syscache\termsrv.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\NBHShellExt]
@="{8D2223A2-B3C6-4e32-B096-CDD11F628C60}"
[HKEY_CLASSES_ROOT\CLSID\{8D2223A2-B3C6-4e32-B096-CDD11F628C60}]
2008-06-10 17:29 97064 —-a-w- c:\program files\Nero\Nero8\InCD\NBHShx.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2010-01-12 13666408]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2010-01-12 110696]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2010-03-02 282792]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"MsnMsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-07-26 3883856]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"_nltide_2"="shell32" [X]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoRecentDocsNetHood"= 1 (0x1)

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoRecentDocsNetHood"= 1 (0x1)

[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoRecentDocsNetHood"= 1 (0x1)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"UIHost"=hex(2):25,53,79,73,74,65,6d,52,6f,6f,74,25,5c,53,79,73,74,65,6d,33,32,\

[HKLM\~\startupfolder\C:^Users^Administrator^Start Menu^Programs^Startup^OpenOffice.org 3.1.lnk]
path=c:\users\Administrator\Start Menu\Programs\Startup\OpenOffice.org 3.1.lnk
backup=c:\windows\pss\OpenOffice.org 3.1.lnkStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
2008-04-14 12:00 15360 ——w- c:\windows\system32\ctfmon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HotKeysCmds]
2003-07-10 09:13 114688 —-a-w- c:\windows\system32\hkcmd.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IgfxTray]
2003-07-10 09:25 155648 —-a-w- c:\windows\system32\igfxtray.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\InCD]
2008-06-10 17:29 1083176 —-a-w- c:\program files\Nero\Nero8\InCD\InCD.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PCTVOICE]
2004-01-30 13:33 180224 —-a-r- c:\windows\system32\pctspk.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UltimateServices]
2009-09-04 00:03 620579 —-a-w- c:\windows\system32\ultsvcs.exe

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
"DisableNotifications"= 1 (0x1)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Sony\\Station\\LaunchPad\\LaunchPad.exe"=

R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe [3/24/2010 8:30 PM 135336]
S4 NeroRegInCDSrv;Nero Registry InCD Service;c:\program files\Nero\Nero8\InCD\NBHRegInCDSrv.exe [6/10/2008 1:29 PM 53032]
.
.
——- Supplementary Scan ——-
.
mStart Page = hxxp://www.yahoo.com
FF - ProfilePath - c:\users\Administrator\Application Data\Mozilla\Firefox\Profiles\uvyx04g7.default\
FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll

—- FIREFOX POLICIES —-
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.debug", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("html5.enable", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pr
ef", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600);
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com");
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20);
.
- - - - ORPHANS REMOVED - - - -

HKLM-Run-nwiz - nwiz.exe
MSConfigStartUp-Cmaudio - cmicnfg.cpl
MSConfigStartUp-Messenger (Yahoo!) - c:\progra~1\Yahoo!\Messenger\YahooMessenger.exe
MSConfigStartUp-Search Protection - c:\program files\Yahoo!\Search Protection\SearchProtection.exe
MSConfigStartUp-YSearchProtection - c:\program files\Yahoo!\Search Protection\SearchProtection.exe
AddRemove-NVIDIA Display Control Panel - c:\program files\NVIDIA Corporation\Uninstall\nvuninst.exe



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-04-01 12:13
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_USERS\S-1-5-21-1844237615-1614895754-1177238915-500\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (Administrator)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,ce,5f,3b,88,0e,97,94,45,b3,53,a9,\
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,ce,5f,3b,88,0e,97,94,45,b3,53,a9,\
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(536)
c:\windows\system32\SETUPAPI.dll
c:\windows\system32\cscui.dll

- - - - - - - > 'lsass.exe'(592)
c:\windows\system32\wdigest.dll
c:\windows\system32\SETUPAPI.dll

- - - - - - - > 'explorer.exe'(3532)
c:\windows\system32\WININET.dll
c:\windows\system32\COMRes.dll
c:\program files\Nero\Nero8\InCD\NBHShx.dll
c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_e6967989\MSVCR80.dll
c:\program files\Nero\Nero8\InCD\NBHStr.dll
c:\program files\Common Files\Nero\Shared\NL3\AdvrCntr3.dll
c:\windows\system32\SETUPAPI.dll
c:\windows\System32\cscui.dll
c:\progra~1\WINDOW~2\wmpband.dll
c:\windows\system32\msi.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\NETSHELL.dll
c:\windows\system32\credui.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\wpdshserviceobj.dll
c:\windows\system32\portabledevicetypes.dll
c:\windows\system32\portabledeviceapi.dll
.
———————— Other Running Processes ————————
.
c:\windows\system32\nvsvc32.exe
c:\windows\system32\RUNDLL32.EXE
c:\program files\Avira\AntiVir Desktop\avguard.exe
c:\windows\eHome\ehRecvr.exe
c:\windows\eHome\ehSched.exe
c:\program files\Avira\AntiVir Desktop\avshadow.exe
c:\program files\Nero\Nero8\InCD\InCDsrv.exe
c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
c:\windows\system32\dllhost.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2010-04-01 12:18:53 - machine was rebooted
ComboFix-quarantined-files.txt 2010-04-01 16:18

Pre-Run: 21,863,829,504 bytes free
Post-Run: 21,878,747,136 bytes free

- - End Of File - - 75830522A7FD82038D406C02DC2A745A
Trilo,

I'm glad it seems better, but we still have work to do:

🖼Click to load external image (Posted Image) Open Notepad Go to Start> All Programs> Assessories> Notepad ( this will only work with Notepad ) and copy all the text inside the Codebox by highlighting it all and pressing CTRL C on your keyboard, then paste it into Notepad, make sure there is no space before and above http://

http://forums.whatthetech.com/Popups_Reboots_t111277.html
Collect::
c:\windows\system32\ultsvcs.exe

Registry::
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"_nltide_2"=-

[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UltimateServices]

SRPeek::
c:\windows\system32\drivers\tcpip.sys
c:\windows\system32\comctl32.dll
c:\windows\system32\user32.dll
c:\windows\explorer.exe
c:\windows\system32\sfcfiles.dll
c:\windows\system32\termsrv.dll

Save this as CFScript to your desktop.

Then drag the CFScript into ComboFix.exe as you see in the screenshot below.

[external image: Posted Image]


This will start ComboFix again. After reboot, (in case it asks to reboot), post the contents of Combofix.txt in your next reply.

🖼Click to load external image (Posted Image) Please download SystemLook from one of the links below and save it to your Desktop.
Download Mirror #1
Download Mirror #2

  • Double-click SystemLook.exe to run it.
  • Copy the content of the following codebox into the main textfield:
    :filefind
    *tcpip*
    *comctl32*
    *user32*
    *explorer*
    *sfcfiles*
    *termsrv*
  • Click the Look button to start the scan.
  • When finished, a notepad window will open with the results of the scan. Please post this log in your next reply.
Note: The log can also be found on your Desktop entitled SystemLook.txt

Please include the following in your next post:
  • ComboFix log
  • SystemLook log
Thank you for such a quick response.

ComboFix log follows:
ComboFix 10-03-29.04 - Administrator 04/01/2010 15:57:59.2.1 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1022.631 [GMT -4:00]
Running from: c:\users\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\users\Administrator\Desktop\CFScript.txt
AV: AntiVir Desktop *On-access scanning disabled* (Outdated) {AD166499-45F9-482A-A743-FDD3350758C7}

file zipped: c:\windows\system32\ultsvcs.exe
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\system32\ultsvcs.exe

.
((((((((((((((((((((((((( Files Created from 2010-03-01 to 2010-04-01 )))))))))))))))))))))))))))))))
.

2010-03-31 18:09 . 2010-03-31 18:09 ——– d—–w- c:\program files\ERUNT
2010-03-26 22:21 . 2010-03-26 22:21 552 —-a-w- c:\windows\system32\d3d8caps.dat
2010-03-25 21:16 . 2010-03-25 21:16 ——– d—–w- c:\users\Administrator\Application Data\GARMIN
2010-03-25 21:15 . 2010-03-25 21:15 ——– d—–w- c:\program files\Garmin GPS Plugin
2010-03-25 21:15 . 2010-03-25 21:15 ——– d—–w- c:\program files\DIFX
2010-03-25 21:15 . 2010-03-25 21:15 ——– d—–w- c:\program files\Garmin
2010-03-25 02:26 . 2010-01-07 20:07 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-03-25 02:26 . 2010-03-25 02:26 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2010-03-25 02:26 . 2010-01-07 20:07 19160 —-a-w- c:\windows\system32\drivers\mbam.sys
2010-03-25 01:42 . 2010-03-25 01:42 ——– d—–w- c:\users\Administrator\Application Data\Avira
2010-03-25 00:30 . 2010-03-01 13:05 124784 —-a-w- c:\windows\system32\drivers\avipbb.sys
2010-03-25 00:30 . 2009-05-11 15:49 45416 —-a-w- c:\windows\system32\drivers\avgntdd.sys
2010-03-25 00:30 . 2009-05-11 15:49 22360 —-a-w- c:\windows\system32\drivers\avgntmgr.sys
2010-03-25 00:30 . 2010-03-25 00:30 ——– d—–w- c:\users\All Users\Application Data\Avira
2010-03-25 00:30 . 2010-03-25 00:30 ——– d—–w- c:\program files\Avira
2010-03-20 23:19 . 2010-03-20 23:19 0 —-a-w- c:\windows\nsreg.dat
2010-03-18 00:00 . 2010-03-18 00:00 ——– d—–w- c:\program files\VS Revo Group
2010-03-17 23:09 . 2010-03-18 00:03 ——– d—–w- c:\program files\Windows Live
2010-03-17 23:08 . 2010-03-17 23:08 ——– d—–w- c:\program files\Microsoft Sync Framework
2010-03-13 15:57 . 2010-03-13 15:57 ——– d—–w- c:\users\Administrator\Local Settings\Application Data\Symantec
2010-03-08 06:07 . 2010-03-08 06:07 ——– d—–w- c:\users\Administrator\MySpaceIM Pics
2010-03-08 06:07 . 2010-03-08 06:07 ——– d—–w- c:\users\\Administrator\MySpaceIM Pics
2010-03-08 06:05 . 2010-03-08 06:06 ——– d—–w- c:\users\Administrator\Application Data\MySpace
2010-03-08 06:05 . 2010-03-13 16:03 ——– d—–w- c:\program files\MySpace
2010-03-08 06:04 . 2010-03-08 06:04 7631232 —-a-w- c:\users\Administrator\Application Data\MySpace\IM\Install\MSIMClientSetup.1.0.823.0-static-A.exe
2010-03-05 22:54 . 2010-03-05 22:54 ——– d—–w- c:\users\All Users\Application Data\McAfee
2010-03-05 00:15 . 2010-03-05 00:15 ——– d—–w- c:\users\Administrator\Local Settings\Application Data\Identities

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-04-01 19:15 . 2010-02-21 02:39 ——– d—–w- c:\program files\Microsoft Silverlight
2010-04-01 15:43 . 2010-02-12 17:27 1 —-a-w- c:\users\Administrator\Application Data\OpenOffice.org\3\user\uno_packages\cache\stamp.sys
2010-04-01 01:13 . 2008-04-14 12:00 96512 ——w- c:\windows\system32\drivers\atapi.sys
2010-03-31 00:35 . 2010-02-26 06:56 664 —-a-w- c:\windows\system32\d3d9caps.dat
2010-03-25 00:23 . 2010-02-12 15:57 ——– d—–w- c:\users\All Users\Application Data\Norton
2010-03-24 21:27 . 2010-02-09 02:51 ——– d–h–w- c:\program files\InstallShield Installation Information
2010-03-24 21:26 . 2010-02-09 02:51 ——– d—–w- c:\program files\Common Files\InstallShield
2010-03-17 22:30 . 2010-02-22 21:20 ——– d—–w- c:\program files\Google
2010-03-12 11:33 . 2010-02-13 02:09 ——– d—–w- c:\users\All Users\Application Data\Yahoo!
2010-03-12 11:32 . 2010-02-13 02:09 ——– d—–w- c:\users\Administrator\Application Data\Yahoo!
2010-02-27 19:17 . 2010-02-27 19:17 ——– d—–w- c:\users\Administrator\Application Data\Malwarebytes
2010-02-27 19:16 . 2010-02-27 19:16 ——– d—–w- c:\users\All Users\Application Data\Malwarebytes
2010-02-25 06:24 . 2009-10-17 22:19 916480 —-a-w- c:\windows\system32\wininet.dll
2010-02-21 02:35 . 2010-02-21 02:35 ——– d—–w- c:\program files\Microsoft
2010-02-21 02:32 . 2010-02-21 02:32 ——– d—–w- c:\program files\Common Files\Windows Live
2010-02-18 22:49 . 2010-02-18 22:49 ——– d—–w- c:\users\Administrator\Application Data\Turbine
2010-02-18 22:49 . 2010-02-18 22:49 119 —-a-w- c:\users\Administrator\Local Settings\Application Data\fusioncache.dat
2010-02-18 21:09 . 2010-02-18 21:09 ——– d—–w- c:\program files\Turbine
2010-02-17 05:11 . 2010-02-17 05:11 ——– d—–w- c:\program files\dx2
2010-02-17 02:43 . 2010-02-17 02:42 ——– d—–w- c:\program files\DX
2010-02-16 17:24 . 2010-02-26 17:58 60936 —-a-w- c:\windows\system32\drivers\avgntflt.sys
2010-02-14 05:47 . 2010-02-14 05:46 ——– d—–w- c:\program files\NVIDIA Corporation
2010-02-14 05:47 . 2010-02-14 05:47 ——– d—–w- c:\users\All Users\Application Data\NVIDIA Corporation
2010-02-14 00:05 . 2010-02-14 00:05 ——– d—–w- c:\program files\AGEIA Technologies
2010-02-14 00:05 . 2010-02-14 00:05 ——– d—–w- c:\program files\Common Files\Wise Installation Wizard
2010-02-13 04:43 . 2010-02-09 01:04 20536 —-a-w- c:\users\Administrator\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-02-13 03:44 . 2010-02-13 03:44 ——– d—–w- c:\users\All Users\Application Data\Symantec
2010-02-13 01:02 . 2010-02-13 00:43 ——– d—–w- c:\program files\Sony
2010-02-13 00:41 . 2010-02-13 00:41 ——– d—–w- c:\program files\Common Files\SWF Studio
2010-02-12 17:26 . 2010-02-12 17:26 ——– d—–w- c:\users\Administrator\Application Data\OpenOffice.org
2010-02-12 17:13 . 2010-02-12 17:13 ——– d—–w- c:\program files\JRE
2010-02-12 17:13 . 2010-02-12 17:13 ——– d—–w- c:\program files\OpenOffice.org 3
2010-02-12 15:57 . 2010-02-12 15:57 ——– d—–w- c:\users\All Users\Application Data\NortonInstaller
2010-02-09 02:56 . 2010-02-09 02:56 1536 —-a-w- c:\windows\system32\TrueSoft.dat
2010-02-09 02:56 . 2010-02-09 02:56 0 —-a-w- c:\windows\system32\PTPTT.dat
2010-02-09 02:56 . 2010-02-09 02:56 0 —-a-w- c:\windows\system32\PTHSP.dat
2010-02-09 01:16 . 2010-02-09 00:58 ——– d—–w- c:\program files\AVG
2010-02-09 00:58 . 2010-02-09 00:13 86811 —-a-w- c:\windows\pchealth\helpctr\OfflineCache\index.dat
2010-02-09 00:51 . 2010-02-09 00:51 ——– d—–w- c:\users\All Users\Application Data\Nero
2010-02-09 00:42 . 2010-02-09 00:42 ——– d—–w- c:\program files\microsoft frontpage
2010-02-09 00:42 . 2010-02-09 00:48 ——– d—a-w- c:\users\Administrator\Application Data\OtakuSoftware
2010-02-09 00:42 . 2010-02-09 00:42 ——– d—a-w- c:\users\Default User\Application Data\OtakuSoftware
2010-02-09 00:42 . 2010-02-09 00:48 ——– d—a-w- c:\users\Administrator\Application Data\Nero
2010-02-09 00:42 . 2010-02-09 00:42 ——– d—a-w- c:\users\Default User\Application Data\Nero
2010-02-09 00:34 . 2010-02-09 00:34 ——– d—–w- c:\program files\Common Files\Adobe
2010-02-09 00:33 . 2010-02-09 00:33 ——– d—–w- c:\program files\TUGZip
2010-02-09 00:32 . 2010-02-09 00:32 411368 —-a-w- c:\windows\system32\deploytk.dll
2010-02-09 00:31 . 2010-02-09 00:31 ——– d—–w- c:\program files\Java
2010-02-09 00:30 . 2010-02-09 00:30 ——– d—–w- c:\program files\MSBuild
2010-02-09 00:30 . 2010-02-09 00:30 ——– d—–w- c:\program files\Reference Assemblies
2010-02-09 00:26 . 2010-02-09 00:25 ——– d—–w- c:\program files\ffdshow
2010-02-09 00:16 . 2010-02-09 00:16 ——– d—–w- c:\program files\Microsoft SQL Server Compact Edition
2010-02-09 00:14 . 2010-02-09 00:14 ——– d—–w- c:\program files\MSXML 4.0
2010-02-09 00:10 . 2010-02-09 00:10 21640 —-a-w- c:\windows\system32\emptyregdb.dat
2010-02-09 00:10 . 2010-02-09 00:10 ——– d—–w- c:\program files\Windows Media Connect 2
2010-01-12 03:17 . 2010-01-12 03:17 278120 —-a-w- c:\windows\system32\nvmccs.dll
2010-01-12 03:17 . 2010-01-12 03:17 154216 —-a-w- c:\windows\system32\nvsvc32.exe
2010-01-12 03:17 . 2010-01-12 03:17 145000 —-a-w- c:\windows\system32\nvcolor.exe
2010-01-12 03:17 . 2010-01-12 03:17 13666408 —-a-w- c:\windows\system32\nvcpl.dll
2010-01-12 03:17 . 2010-01-12 03:17 110696 —-a-w- c:\windows\system32\nvmctray.dll
2010-01-12 03:17 . 2010-01-12 03:17 81920 —-a-w- c:\windows\system32\nvwddi.dll
.

(((((((((((((((((((((((((((((((((((((((((( SR_Search ))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
——- Sigcheck ——-

[-] 2009-08-28 . F470A27484E43DA058BDFC235CD67FD1 . 361600 . . [5.1.2600.9999] . . c:\windows\system32\drivers\tcpip.sys
[-] 2009-08-28 . F470A27484E43DA058BDFC235CD67FD1 . 361600 . . [5.1.2600.9999] . . c:\windows\system32\syscache\tcpip.sys

[-] 2009-10-17 . C9FB1A9B3F9B51F08B665542DDFEE295 . 692736 . . [5.82] . . c:\windows\system32\comctl32.dll

[-] 2009-10-17 . 6616894470538493B9AAE74271F099EF . 578048 . . [5.1.2600.5512] . . c:\windows\system32\user32.dll

[-] 2009-10-17 . AEA58E2C358B987FCC612907377373C3 . 1697280 . . [6.00.2900.5512] . . c:\windows\explorer.exe

[-] 2009-10-17 . 362BC5AF8EAF712832C58CC13AE05750 . 1614848 . . [5.1.2600.5512] . . c:\windows\system32\sfcfiles.dll

[-] 2009-09-11 . EE87B66DBB4D5C44E94854118664EF42 . 295424 . . [5.1.2600.9999] . . c:\windows\system32\termsrv.dll
[-] 2009-09-11 . EE87B66DBB4D5C44E94854118664EF42 . 295424 . . [5.1.2600.9999] . . c:\windows\system32\syscache\termsrv.dll
.
((((((((((((((((((((((((((((( SnapShot@2010-04-01_16.14.02 )))))))))))))))))))))))))))))))))))))))))
.
+ 2008-04-14 12:00 . 2010-01-23 08:11 46080 c:\windows\system32\tzchange.exe
- 2008-04-14 12:00 . 2009-10-28 15:07 46080 c:\windows\system32\tzchange.exe
- 2008-04-14 12:00 . 2010-03-14 20:30 71612 c:\windows\system32\perfc009.dat
+ 2008-04-14 12:00 . 2010-04-01 16:18 71612 c:\windows\system32\perfc009.dat
+ 2009-10-17 22:19 . 2010-02-25 06:24 55296 c:\windows\system32\msfeedsbs.dll
- 2009-10-17 22:19 . 2009-12-21 19:14 55296 c:\windows\system32\msfeedsbs.dll
- 2009-10-17 22:19 . 2009-12-21 19:14 25600 c:\windows\system32\jsproxy.dll
+ 2009-10-17 22:19 . 2010-02-25 06:24 25600 c:\windows\system32\jsproxy.dll
+ 2010-02-09 01:46 . 2010-02-25 06:24 12800 c:\windows\system32\dllcache\xpshims.dll
- 2010-02-09 01:46 . 2009-12-21 19:14 12800 c:\windows\system32\dllcache\xpshims.dll
+ 2010-02-09 00:15 . 2010-02-25 06:24 55296 c:\windows\system32\dllcache\msfeedsbs.dll
- 2010-02-09 00:15 . 2009-12-21 19:14 55296 c:\windows\system32\dllcache\msfeedsbs.dll
+ 2009-10-17 22:19 . 2010-02-25 06:24 25600 c:\windows\system32\dllcache\jsproxy.dll
- 2009-10-17 22:19 . 2009-12-21 19:14 25600 c:\windows\system32\dllcache\jsproxy.dll
+ 2010-04-01 19:09 . 2009-12-21 19:14 12800 c:\windows\ie8updates\KB980182-IE8\xpshims.dll
+ 2010-04-01 19:09 . 2009-12-21 19:14 55296 c:\windows\ie8updates\KB980182-IE8\msfeedsbs.dll
+ 2010-04-01 19:09 . 2009-12-21 19:14 25600 c:\windows\ie8updates\KB980182-IE8\jsproxy.dll
- 2008-04-14 12:00 . 2010-03-14 20:30 441786 c:\windows\system32\perfh009.dat
+ 2008-04-14 12:00 . 2010-04-01 16:18 441786 c:\windows\system32\perfh009.dat
- 2009-10-17 22:19 . 2009-12-21 19:14 206848 c:\windows\system32\occache.dll
+ 2009-10-17 22:19 . 2010-02-25 06:24 206848 c:\windows\system32\occache.dll
+ 2009-10-17 22:19 . 2010-02-25 06:24 611840 c:\windows\system32\mstime.dll
- 2009-10-17 22:19 . 2009-03-08 09:32 611840 c:\windows\system32\mstime.dll
+ 2009-10-17 22:19 . 2010-02-25 06:24 594432 c:\windows\system32\msfeeds.dll
- 2009-10-17 22:19 . 2009-12-21 19:14 594432 c:\windows\system32\msfeeds.dll
+ 2009-10-17 22:24 . 2009-12-09 05:53 726528 c:\windows\system32\jscript.dll
- 2009-10-17 22:24 . 2009-06-22 06:44 726528 c:\windows\system32\jscript.dll
- 2009-10-17 22:19 . 2009-12-21 19:14 184320 c:\windows\system32\iepeers.dll
+ 2009-10-17 22:19 . 2010-02-25 06:24 184320 c:\windows\system32\iepeers.dll
+ 2009-10-17 22:19 . 2010-02-25 06:24 387584 c:\windows\system32\iedkcs32.dll
- 2009-10-17 22:19 . 2009-12-21 19:14 387584 c:\windows\system32\iedkcs32.dll
+ 2009-10-17 22:19 . 2010-02-24 09:54 173056 c:\windows\system32\ie4uinit.exe
- 2009-10-17 22:19 . 2009-12-21 13:19 173056 c:\windows\system32\ie4uinit.exe
- 2009-10-17 22:19 . 2009-12-21 19:14 916480 c:\windows\system32\dllcache\wininet.dll
+ 2009-10-17 22:19 . 2010-02-25 06:24 916480 c:\windows\system32\dllcache\wininet.dll
+ 2009-10-17 22:19 . 2010-02-25 06:24 206848 c:\windows\system32\dllcache\occache.dll
- 2009-10-17 22:19 . 2009-12-21 19:14 206848 c:\windows\system32\dllcache\occache.dll
- 2009-10-17 22:19 . 2009-03-08 09:32 611840 c:\windows\system32\dllcache\mstime.dll
+ 2009-10-17 22:19 . 2010-02-25 06:24 611840 c:\windows\system32\dllcache\mstime.dll
+ 2010-02-09 00:15 . 2010-02-25 06:24 594432 c:\windows\system32\dllcache\msfeeds.dll
- 2010-02-09 00:15 . 2009-12-21 19:14 594432 c:\windows\system32\dllcache\msfeeds.dll
- 2009-10-17 22:24 . 2009-06-22 06:44 726528 c:\windows\system32\dllcache\jscript.dll
+ 2009-10-17 22:24 . 2009-12-09 05:53 726528 c:\windows\system32\dllcache\jscript.dll
+ 2010-02-09 01:46 . 2010-02-25 06:24 247808 c:\windows\system32\dllcache\ieproxy.dll
- 2009-10-17 22:19 . 2009-12-21 19:14 184320 c:\windows\system32\dllcache\iepeers.dll
+ 2009-10-17 22:19 . 2010-02-25 06:24 184320 c:\windows\system32\dllcache\iepeers.dll
+ 2009-10-17 22:19 . 2010-02-25 06:24 387584 c:\windows\system32\dllcache\iedkcs32.dll
- 2009-10-17 22:19 . 2009-12-21 19:14 387584 c:\windows\system32\dllcache\iedkcs32.dll
+ 2009-10-17 22:19 . 2010-02-24 09:54 173056 c:\windows\system32\dllcache\ie4uinit.exe
- 2009-10-17 22:19 . 2009-12-21 13:19 173056 c:\windows\system32\dllcache\ie4uinit.exe
+ 2010-04-01 19:07 . 2010-04-01 19:07 177664 c:\windows\Installer\96dcda.msi
+ 2010-04-01 19:09 . 2009-12-21 19:14 916480 c:\windows\ie8updates\KB980182-IE8\wininet.dll
+ 2010-04-01 19:09 . 2009-05-26 11:40 382840 c:\windows\ie8updates\KB980182-IE8\spuninst\updspapi.dll
+ 2010-04-01 19:09 . 2009-05-26 11:40 231288 c:\windows\ie8updates\KB980182-IE8\spuninst\spuninst.exe
+ 2010-04-01 19:09 . 2009-12-21 19:14 206848 c:\windows\ie8updates\KB980182-IE8\occache.dll
+ 2010-04-01 19:09 . 2009-03-08 09:32 611840 c:\windows\ie8updates\KB980182-IE8\mstime.dll
+ 2010-04-01 19:09 . 2009-12-21 19:14 594432 c:\windows\ie8updates\KB980182-IE8\msfeeds.dll
+ 2010-04-01 19:09 . 2009-12-21 19:14 246272 c:\windows\ie8updates\KB980182-IE8\ieproxy.dll
+ 2010-04-01 19:09 . 2009-12-21 19:14 184320 c:\windows\ie8updates\KB980182-IE8\iepeers.dll
+ 2010-04-01 19:09 . 2009-12-21 19:14 387584 c:\windows\ie8updates\KB980182-IE8\iedkcs32.dll
+ 2010-04-01 19:09 . 2009-12-21 13:19 173056 c:\windows\ie8updates\KB980182-IE8\ie4uinit.exe
+ 2010-04-01 19:07 . 2008-07-08 13:02 382840 c:\windows\ie8updates\KB976662-IE8\spuninst\updspapi.dll
+ 2010-04-01 19:07 . 2008-07-08 13:02 231288 c:\windows\ie8updates\KB976662-IE8\spuninst\spuninst.exe
+ 2010-04-01 19:07 . 2009-06-22 06:44 726528 c:\windows\ie8updates\KB976662-IE8\jscript.dll
+ 2009-10-17 22:19 . 2010-02-25 06:24 1209344 c:\windows\system32\urlmon.dll
+ 2009-10-17 22:19 . 2010-02-25 06:24 5944832 c:\windows\system32\mshtml.dll
- 2009-10-17 22:19 . 2009-12-21 19:14 1985536 c:\windows\system32\iertutil.dll
+ 2009-10-17 22:19 . 2010-02-25 06:24 1985536 c:\windows\system32\iertutil.dll
+ 2009-10-17 22:19 . 2010-02-25 06:24 1209344 c:\windows\system32\dllcache\urlmon.dll
+ 2009-10-17 22:19 . 2010-02-25 06:24 5944832 c:\windows\system32\dllcache\mshtml.dll
- 2010-02-09 00:11 . 2008-04-14 12:00 3558912 c:\windows\system32\dllcache\moviemk.exe
+ 2010-02-09 00:11 . 2009-10-23 15:28 3558912 c:\windows\system32\dllcache\moviemk.exe
- 2010-02-09 00:15 . 2009-12-21 19:14 1985536 c:\windows\system32\dllcache\iertutil.dll
+ 2010-02-09 00:15 . 2010-02-25 06:24 1985536 c:\windows\system32\dllcache\iertutil.dll
+ 2010-04-01 19:09 . 2009-12-21 19:14 1208832 c:\windows\ie8updates\KB980182-IE8\urlmon.dll
+ 2010-04-01 19:09 . 2009-12-21 19:14 5942784 c:\windows\ie8updates\KB980182-IE8\mshtml.dll
+ 2010-04-01 19:09 . 2009-12-21 19:14 1985536 c:\windows\ie8updates\KB980182-IE8\iertutil.dll
+ 2010-02-09 01:36 . 2010-03-02 05:30 31648712 c:\windows\system32\MRT.exe
+ 2009-10-17 22:19 . 2010-02-25 15:54 11070976 c:\windows\system32\ieframe.dll
+ 2010-02-09 00:15 . 2010-02-25 15:54 11070976 c:\windows\system32\dllcache\ieframe.dll
+ 2010-04-01 19:07 . 2010-04-01 19:07 15710720 c:\windows\Installer\96dce1.msp
+ 2010-04-01 19:09 . 2009-12-21 19:14 11070464 c:\windows\ie8updates\KB980182-IE8\ieframe.dll
.
– Snapshot reset to current date –
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\NBHShellExt]
@="{8D2223A2-B3C6-4e32-B096-CDD11F628C60}"
[HKEY_CLASSES_ROOT\CLSID\{8D2223A2-B3C6-4e32-B096-CDD11F628C60}]
2008-06-10 17:29 97064 —-a-w- c:\program files\Nero\Nero8\InCD\NBHShx.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2010-01-12 13666408]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2010-01-12 110696]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2010-03-02 282792]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"MsnMsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-07-26 3883856]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoRecentDocsNetHood"= 1 (0x1)

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoRecentDocsNetHood"= 1 (0x1)

[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoRecentDocsNetHood"= 1 (0x1)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"UIHost"=hex(2):25,53,79,73,74,65,6d,52,6f,6f,74,25,5c,53,79,73,74,65,6d,33,32,\

[HKLM\~\startupfolder\C:^Users^Administrator^Start Menu^Programs^Startup^OpenOffice.org 3.1.lnk]
path=c:\users\Administrator\Start Menu\Programs\Startup\OpenOffice.org 3.1.lnk
backup=c:\windows\pss\OpenOffice.org 3.1.lnkStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
2008-04-14 12:00 15360 ——w- c:\windows\system32\ctfmon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HotKeysCmds]
2003-07-10 09:13 114688 —-a-w- c:\windows\system32\hkcmd.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IgfxTray]
2003-07-10 09:25 155648 —-a-w- c:\windows\system32\igfxtray.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\InCD]
2008-06-10 17:29 1083176 —-a-w- c:\program files\Nero\Nero8\InCD\InCD.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PCTVOICE]
2004-01-30 13:33 180224 —-a-r- c:\windows\system32\pctspk.exe

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
"DisableNotifications"= 1 (0x1)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Sony\\Station\\LaunchPad\\LaunchPad.exe"=

R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe [3/24/2010 8:30 PM 135336]
S4 NeroRegInCDSrv;Nero Registry InCD Service;c:\program files\Nero\Nero8\InCD\NBHRegInCDSrv.exe [6/10/2008 1:29 PM 53032]
.
.
——- Supplementary Scan ——-
.
mStart Page = hxxp://www.yahoo.com
FF - ProfilePath - c:\users\Administrator\Application Data\Mozilla\Firefox\Profiles\uvyx04g7.default\
FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll

—- FIREFOX POLICIES —-
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.debug", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("html5.enable", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pr
ef", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600);
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com");
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20);
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-04-01 16:02
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_USERS\S-1-5-21-1844237615-1614895754-1177238915-500\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (Administrator)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,ce,5f,3b,88,0e,97,94,45,b3,53,a9,\
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,ce,5f,3b,88,0e,97,94,45,b3,53,a9,\
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(540)
c:\windows\system32\SETUPAPI.dll
c:\windows\system32\cscui.dll

- - - - - - - > 'lsass.exe'(596)
c:\windows\system32\wdigest.dll
c:\windows\system32\SETUPAPI.dll
.
Completion time: 2010-04-01 16:05:25
ComboFix-quarantined-files.txt 2010-04-01 20:05
ComboFix2.txt 2010-04-01 16:18

Pre-Run: 21,642,989,568 bytes free
Post-Run: 21,615,886,336 bytes free

- - End Of File - - 8B728AF8A27CBC97CCE71D62562DFEA3
Upload was successful


SystemLook log follows:
SystemLook v1.0 by jpshortstuff (11.01.10)
Log created at 16:10 on 01/04/2010 by Administrator (Administrator - Elevation successful)

========== filefind ==========

Searching for "*tcpip*"
C:\Qoobox\Quarantine\Registry_backups\tcpip.reg –a— 5002 bytes [16:11 01/04/2010] [20:02 01/04/2010] B0B892137D0EE50942C6E5B4C14E1E02
C:\WINDOWS\Help\tcpip.chm –a— 50586 bytes [12:00 14/04/2008] [12:00 14/04/2008] 24FC18A9ED0AA561C5F5DC295F9AA9F2
C:\WINDOWS\inf\nettcpip.inf –a— 24362 bytes [12:00 14/04/2008] [12:00 14/04/2008] 063AB8BAD83E9238108FE25E04F8632F
C:\WINDOWS\inf\nettcpip.PNF –a— 39216 bytes [19:03 08/02/2010] [01:13 09/02/2010] 5862C1CAC0ED0C4110E2CCD93BA22AA8
C:\WINDOWS\system32\dllcache\tcpip6.sys –a–c 225856 bytes [22:21 17/10/2009] [22:21 17/10/2009] 026A94E4EB2960FDC96A447B5391D56A
C:\WINDOWS\system32\dllcache\wshtcpip.dll –a–c 19456 bytes [12:00 14/04/2008] [12:00 14/04/2008] 4E3D06D6E68EEDB52565080F55B460D3
C:\WINDOWS\system32\drivers\tcpip.sys –a— 361600 bytes [20:24 28/08/2009] [20:24 28/08/2009] F470A27484E43DA058BDFC235CD67FD1
C:\WINDOWS\system32\drivers\tcpip6.sys –a— 225856 bytes [22:21 17/10/2009] [22:21 17/10/2009] 026A94E4EB2960FDC96A447B5391D56A
C:\WINDOWS\system32\syscache\tcpip.sys –a— 361600 bytes [00:42 09/02/2010] [20:24 28/08/2009] F470A27484E43DA058BDFC235CD67FD1
C:\WINDOWS\system32\wshtcpip.dll –a— 19456 bytes [12:00 14/04/2008] [12:00 14/04/2008] 4E3D06D6E68EEDB52565080F55B460D3

Searching for "*comctl32*"
C:\WINDOWS\system32\comctl32.dll –a— 692736 bytes [22:53 17/10/2009] [22:53 17/10/2009] C9FB1A9B3F9B51F08B665542DDFEE295
C:\WINDOWS\system32\Libraries\vcomctl32.dll –a— 96208 bytes [05:00 23/03/2008] [05:00 23/03/2008] 206BE0A46582E4C3266C13D008FAEF6D
C:\WINDOWS\system32\syscache\comctl32.ult –a— 80936 bytes [20:20 02/08/2007] [20:20 02/08/2007] CD19F7982C78558859102E4C7466F1C5
C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.0.0_x-ww_1382d70a\comctl32.dll -ra— 921088 bytes [18:40 08/02/2010] [12:00 14/04/2008] AEF3D788DBF40C7C4D204EA45EB0C505
C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.5512_x-ww_35d4ce83\comctl32.dll –a— 1054208 bytes [18:40 08/02/2010] [12:00 14/04/2008] BD38D1EBE24A46BD3EDA059560AFBA12

Searching for "*user32*"
C:\WINDOWS\system32\Libraries\vuser32.dll –a— 40400 bytes [05:01 23/03/2008] [05:01 23/03/2008] 8FCFE2FDFFD8BF1371B30BE1106F32A3
C:\WINDOWS\system32\syscache\user32.ult –a— 144076 bytes [12:33 03/08/2007] [12:33 03/08/2007] 129C1C4A14618045C144CE3748175E9B
C:\WINDOWS\system32\user32.dll –a— 578048 bytes [22:53 17/10/2009] [22:53 17/10/2009] 6616894470538493B9AAE74271F099EF

Searching for "*explorer*"
C:\Users\Administrator\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk –a— 815 bytes [02:03 09/02/2010] [02:03 09/02/2010] A0809690AD015DD7234E9055F3339A94
C:\Users\Administrator\Application Data\Microsoft\Internet Explorer\Quick Launch\Windows Explorer.lnk –a— 1493 bytes [00:48 09/02/2010] [21:38 25/03/2010] E1FC531AF162B37E5E7BDD63986FB805
C:\Users\Administrator\Start Menu\Programs\Accessories\System Tools\Internet Explorer (No Add-ons).lnk –a— 833 bytes [01:02 09/02/2010] [02:03 09/02/2010] EF862DFE54D1202964AE86D6DD60FE80
C:\Users\Administrator\Start Menu\Programs\Accessories\Windows Explorer.lnk –a— 1487 bytes [00:48 09/02/2010] [00:12 09/02/2010] 07F3B9BCE1414F5A593FF0CA2D02AECA
C:\Users\Administrator\Start Menu\Programs\Internet Explorer.lnk –a— 803 bytes [01:02 09/02/2010] [02:03 09/02/2010] 248A9FAC439190517007A7A9EFEA1E61
C:\Users\Default User\Application Data\Microsoft\Internet Explorer\Quick Launch\Windows Explorer.lnk –a— 1493 bytes [00:42 09/02/2010] [12:32 30/06/2007] 8C41B3E30B9A8F79BA32FE47A11A7092
C:\Users\Default User\Start Menu\Programs\Accessories\Windows Explorer.lnk –a— 1487 bytes [00:12 09/02/2010] [00:12 09/02/2010] 07F3B9BCE1414F5A593FF0CA2D02AECA
C:\WINDOWS\explorer.exe –a— 1697280 bytes [22:53 17/10/2009] [22:53 17/10/2009] AEA58E2C358B987FCC612907377373C3
C:\WINDOWS\explorer.scf –a— 80 bytes [12:00 14/04/2008] [12:00 14/04/2008] A3975A7D2C98B30A2AE010754FFB9392
C:\WINDOWS\Prefetch\EXPLORER.EXE-082F38A9.pf –a— 120198 bytes [01:36 25/03/2010] [20:09 01/04/2010] 4A72FEF0E83F3DFCE30E2E60ED4459D2
C:\WINDOWS\system32\config\systemprofile\Application Data\Microsoft\Internet Explorer\Quick Launch\Windows Explorer.lnk –a— 1493 bytes [00:46 09/02/2010] [12:32 30/06/2007] 8C41B3E30B9A8F79BA32FE47A11A7092
C:\WINDOWS\system32\config\systemprofile\Start Menu\Programs\Accessories\Windows Explorer.lnk –a— 1487 bytes [00:46 09/02/2010] [00:12 09/02/2010] 07F3B9BCE1414F5A593FF0CA2D02AECA
C:\WINDOWS\system32\syscache\explorer.ult –a— 1229528 bytes [00:39 09/01/2009] [00:39 09/01/2009] DF26057E21877FCDBA1A1F8C4C00C61D

Searching for "*sfcfiles*"
C:\WINDOWS\system32\sfcfiles.dll –a— 1614848 bytes [22:35 17/10/2009] [22:35 17/10/2009] 362BC5AF8EAF712832C58CC13AE05750

Searching for "*termsrv*"
C:\WINDOWS\system32\syscache\termsrv.dll –a— 295424 bytes [00:42 09/02/2010] [12:23 11/09/2009] EE87B66DBB4D5C44E94854118664EF42
C:\WINDOWS\system32\termsrv.dll –a— 295424 bytes [00:09 09/02/2010] [12:23 11/09/2009] EE87B66DBB4D5C44E94854118664EF42

-=End Of File=-
Trilo,

You have a few bad system files that need to be replaced. If I can't find a good copy on your system you will need a Windows XP disk.

🖼Click to load external image (Posted Image) Download OTL to your desktop.
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Under the Custom Scan box paste this in:
    /md5start
    tcpip.sys
    comctl32.dll
    user32.dll
    explorer.exe
    sfcfiles.dll
    termsrv.dll
    /md5stop
    CREATERESTOREPOINT


  • Click the Quick Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time.
Please include the following in your next post:
  • OTL log
OTL.txt contents follows: (Extras.txt is at the bottom)
OTL logfile created on: 4/1/2010 10:31:58 PM - Run 1
OTL by OldTimer - Version 3.1.37.3 Folder = C:\Users\Administrator\Desktop
Windows XP Media Center Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1,022.00 Mb Total Physical Memory | 698.00 Mb Available Physical Memory | 68.00% Memory free
2.00 Gb Paging File | 2.00 Gb Available in Paging File | 84.00% Paging File free
Paging file location(s): C:\pagefile.sys 1533 2500 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 37.24 Gb Total Space | 20.14 Gb Free Space | 54.09% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: ANY-B33CA27F5BF
Current User Name: Administrator
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: On
Skip Microsoft Files: On
File Age = 14 Days
Output = Minimal
Quick Scan

========== Processes (SafeList) ==========

PRC - C:\Users\Administrator\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Avira GmbH)
PRC - C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
PRC - C:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira GmbH)
PRC - C:\Program Files\Avira\AntiVir Desktop\avshadow.exe (Avira GmbH)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe (Microsoft Corporation)
PRC - C:\Program Files\Nero\Nero8\InCD\InCDsrv.exe (Nero AG)


========== Modules (SafeList) ==========

MOD - C:\Users\Administrator\Desktop\OTL.exe (OldTimer Tools)


========== Win32 Services (SafeList) ==========

SRV - (AntiVirService) – C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Avira GmbH)
SRV - (AntiVirSchedulerService) – C:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira GmbH)
SRV - (fsssvc) – C:\Program Files\Windows Live\Family Safety\fsssvc.exe (Microsoft Corporation)
SRV - (SeaPort) – C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe (Microsoft Corporation)
SRV - (InCDsrv) – C:\Program Files\Nero\Nero8\InCD\InCDsrv.exe (Nero AG)
SRV - (NeroRegInCDSrv) – C:\Program Files\Nero\Nero8\InCD\NBHRegInCDSrv.exe (Nero AG)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://www.msn.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-us
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = C5 44 9D 99 FB D0 CA 01 [binary data]
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========


FF - HKLM\software\mozilla\Mozilla Firefox 3.6.2\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/03/26 16:23:15 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.2\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/03/26 16:23:14 | 000,000,000 | —D | M]

[2010/03/18 20:37:07 | 000,000,000 | —D | M] – C:\Users\Administrator\Application Data\Mozilla\Extensions
[2010/03/18 20:37:07 | 000,000,000 | —D | M] – C:\Users\Administrator\Application Data\Mozilla\Firefox\Profiles\uvyx04g7.default\extensions
[2010/03/24 21:40:24 | 000,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions

O1 HOSTS File: ([2010/04/01 12:13:27 | 000,000,027 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
O2 - BHO: (Search Helper) - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll (Microsoft Corporation)
O2 - BHO: (Windows Live Toolbar Helper) - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
O3 - HKLM\..\Toolbar: (&Windows Live Toolbar) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (&Windows Live Toolbar) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
O4 - HKLM..\Run: [avgnt] C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\WINDOWS\System32\NvMcTray.DLL (NVIDIA Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoRecentDocsNetHood = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoRecentDocsNetHood = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O9 - Extra Button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_16)
O16 - DPF: {CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_16)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_16)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed]
O18 - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Program Files\Windows Live\Mail\mailcomm.dll (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UIHost - (%SystemRoot%\System32\ultlogonui.exe) - C:\WINDOWS\system32\ultlogonui.exe (Microsoft Corporation)
O20 - Winlogon\Notify\igfxcui: DllName - igfxsrvc.dll - C:\WINDOWS\System32\igfxsrvc.dll (Intel Corporation)
O24 - Desktop WallPaper: C:\Users\Administrator\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Users\Administrator\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {AEB6717E-7E19-11d0-97EE-00C04FD91972} - Reg Error: Key error. File not found
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = secfile] – Reg Error: Key error. File not found
O37 - HKCU\…exe [@ = exefile] – Reg Error: Key error. File not found

CREATERESTOREPOINT
Restore point Set: OTL Restore Point (16891891626803200)

========== Files/Folders - Created Within 14 Days ==========

[2010/04/01 22:28:09 | 000,555,520 | —- | C] (OldTimer Tools) – C:\Users\Administrator\Desktop\OTL.exe
[2010/04/01 16:06:15 | 000,000,000 | —D | C] – C:\WINDOWS\temp
[2010/04/01 12:00:46 | 000,212,480 | —- | C] (SteelWerX) – C:\WINDOWS\SWXCACLS.exe
[2010/04/01 12:00:46 | 000,161,792 | —- | C] (SteelWerX) – C:\WINDOWS\SWREG.exe
[2010/04/01 12:00:46 | 000,136,704 | —- | C] (SteelWerX) – C:\WINDOWS\SWSC.exe
[2010/04/01 12:00:46 | 000,031,232 | —- | C] (NirSoft) – C:\WINDOWS\NIRCMD.exe
[2010/04/01 11:59:56 | 000,000,000 | —D | C] – C:\Qoobox
[2010/04/01 11:38:06 | 000,000,000 | —D | C] – C:\Users\Administrator\Desktop\Pics
[2010/03/31 14:09:52 | 000,000,000 | —D | C] – C:\WINDOWS\ERDNT
[2010/03/31 14:09:09 | 000,000,000 | —D | C] – C:\Program Files\ERUNT
[2010/03/30 13:47:42 | 000,000,000 | —D | C] – C:\Users\Administrator\Desktop\Eldest_files
[2010/03/30 12:42:32 | 000,000,000 | —D | C] – C:\Users\Administrator\Desktop\Jeep Pictures
[2010/03/25 17:16:02 | 000,000,000 | —D | C] – C:\Users\Administrator\Application Data\GARMIN
[2010/03/25 17:15:34 | 000,000,000 | —D | C] – C:\Program Files\Garmin GPS Plugin
[2010/03/25 17:15:31 | 000,000,000 | —D | C] – C:\Program Files\DIFX
[2010/03/25 17:15:30 | 000,000,000 | —D | C] – C:\Program Files\Garmin
[2010/03/24 22:26:28 | 000,038,224 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2010/03/24 22:26:25 | 000,019,160 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2010/03/24 22:26:25 | 000,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2010/03/24 21:42:55 | 000,000,000 | —D | C] – C:\Users\Administrator\Application Data\Avira
[2010/03/24 20:30:50 | 000,124,784 | —- | C] (Avira GmbH) – C:\WINDOWS\System32\drivers\avipbb.sys
[2010/03/24 20:30:50 | 000,045,416 | —- | C] (Avira GmbH) – C:\WINDOWS\System32\drivers\avgntdd.sys
[2010/03/24 20:30:50 | 000,028,520 | —- | C] (Avira GmbH) – C:\WINDOWS\System32\drivers\ssmdrv.sys
[2010/03/24 20:30:50 | 000,022,360 | —- | C] (Avira GmbH) – C:\WINDOWS\System32\drivers\avgntmgr.sys
[2010/03/24 20:30:49 | 000,000,000 | —D | C] – C:\Users\All Users\Application Data\Avira
[2010/03/24 20:30:49 | 000,000,000 | —D | C] – C:\Program Files\Avira
[2010/03/11 01:49:01 | 000,000,000 | —D | M] – C:\Users\LocalService\Application Data\Macromedia
[2010/03/11 01:48:58 | 000,000,000 | —D | M] – C:\Users\LocalService\Application Data\Adobe
[2010/02/26 02:56:57 | 000,000,000 | —D | M] – C:\Users\NetworkService\Local Settings\Application Data\Adobe
[2010/02/26 02:56:55 | 000,000,000 | —D | M] – C:\Users\NetworkService\Application Data\Adobe
[2010/02/26 02:56:49 | 000,000,000 | —D | M] – C:\Users\NetworkService\Application Data\Sun
[2010/02/25 20:09:36 | 000,000,000 | —D | M] – C:\Users\NetworkService\Application Data\Macromedia
[2010/02/22 17:25:01 | 000,000,000 | —D | M] – C:\Users\NetworkService\Local Settings\Application Data\Google
[2010/02/22 17:20:59 | 000,000,000 | —D | M] – C:\Users\LocalService\Local Settings\Application Data\Google
[2010/02/12 11:09:13 | 000,000,000 | –SD | M] – C:\Users\NetworkService\Local Settings\Application Data\Microsoft
[2010/02/12 11:09:13 | 000,000,000 | –SD | M] – C:\Users\NetworkService\Application Data\Microsoft
[2010/02/12 11:09:13 | 000,000,000 | –SD | M] – C:\Users\LocalService\Local Settings\Application Data\Microsoft
[2010/02/12 11:09:13 | 000,000,000 | –SD | M] – C:\Users\LocalService\Application Data\Microsoft
[3 C:\WINDOWS\System32\drivers\*.tmp files -> C:\WINDOWS\System32\drivers\*.tmp -> ]
[3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files - Modified Within 14 Days ==========

[2010/04/01 22:27:54 | 000,555,520 | —- | M] (OldTimer Tools) – C:\Users\Administrator\Desktop\OTL.exe
[2010/04/01 17:38:39 | 000,001,657 | —- | M] () – C:\Users\All Users\Desktop\EverQuest.lnk
[2010/04/01 16:09:04 | 000,100,908 | —- | M] () – C:\Users\Administrator\Desktop\SystemLook.exe
[2010/04/01 16:05:26 | 000,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2010/04/01 16:03:01 | 000,000,227 | —- | M] () – C:\WINDOWS\system.ini
[2010/04/01 15:15:10 | 000,271,490 | —- | M] () – C:\WINDOWS\System32\NvApps.xml
[2010/04/01 15:15:04 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2010/04/01 15:14:17 | 002,621,440 | -H– | M] () – C:\Users\Administrator\NTUSER.DAT
[2010/04/01 15:14:00 | 005,357,372 | -H– | M] () – C:\Users\Administrator\Local Settings\Application Data\IconCache.db
[2010/04/01 15:09:20 | 000,001,355 | —- | M] () – C:\WINDOWS\imsins.BAK
[2010/04/01 15:04:50 | 000,002,206 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2010/04/01 12:18:49 | 000,441,786 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2010/04/01 12:18:49 | 000,071,612 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2010/04/01 12:18:48 | 000,521,942 | —- | M] () – C:\WINDOWS\System32\PerfStringBackup.INI
[2010/04/01 12:13:27 | 000,000,027 | —- | M] () – C:\WINDOWS\System32\drivers\etc\hosts
[2010/04/01 11:55:23 | 003,906,159 | R— | M] () – C:\Users\Administrator\Desktop\ComboFix.exe
[2010/03/31 14:17:26 | 000,293,376 | —- | M] () – C:\Users\Administrator\Desktop\eclzvb7p.exe
[2010/03/31 14:13:26 | 000,359,929 | —- | M] () – C:\Users\Administrator\Desktop\dds.scr
[2010/03/31 14:09:09 | 000,000,611 | —- | M] () – C:\Users\Administrator\Desktop\NTREGOPT.lnk
[2010/03/31 14:09:09 | 000,000,592 | —- | M] () – C:\Users\Administrator\Desktop\ERUNT.lnk
[2010/03/31 13:55:33 | 000,021,504 | —- | M] (Doug Knox) – C:\Users\Administrator\Desktop\SysRestorePoint.exe
[2010/03/30 20:35:24 | 000,000,664 | —- | M] () – C:\WINDOWS\System32\d3d9caps.dat
[2010/03/30 13:47:42 | 000,103,737 | —- | M] () – C:\Users\Administrator\Desktop\Eldest.htm
[2010/03/30 13:31:38 | 000,000,149 | —- | M] () – C:\Users\Administrator\Desktop\Butterflies (Blue Morpho or Cyrbia).url
[2010/03/30 12:51:20 | 000,550,145 | —- | M] () – C:\Users\Administrator\Desktop\Lilies.jpg
[2010/03/30 12:50:56 | 000,678,623 | —- | M] () – C:\Users\Administrator\Desktop\Lizard!.jpg
[2010/03/30 12:50:34 | 000,365,359 | —- | M] () – C:\Users\Administrator\Desktop\Hearse.jpg
[2010/03/26 18:21:18 | 000,000,552 | —- | M] () – C:\WINDOWS\System32\d3d8caps.dat
[2010/03/25 18:03:31 | 000,000,178 | -HS- | M] () – C:\Users\Administrator\ntuser.ini
[2010/03/24 22:26:31 | 000,000,696 | —- | M] () – C:\Users\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/03/24 20:31:08 | 000,001,707 | —- | M] () – C:\Users\All Users\Desktop\Avira AntiVir Control Center.lnk
[2010/03/20 20:18:07 | 000,000,069 | —- | M] () – C:\WINDOWS\NeroDigital.ini
[2010/03/20 19:47:05 | 000,003,584 | —- | M] () – C:\Users\Administrator\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/03/20 19:29:03 | 000,377,344 | -HS- | M] () – C:\ehthumbs.db
[2010/03/20 19:19:38 | 000,000,000 | —- | M] () – C:\WINDOWS\nsreg.dat
[2010/03/19 21:42:31 | 000,009,912 | —- | M] () – C:\Users\Administrator\Desktop\eqclient.ini
[3 C:\WINDOWS\System32\drivers\*.tmp files -> C:\WINDOWS\System32\drivers\*.tmp -> ]
[3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files Created - No Company Name ==========

[2010/04/01 16:09:08 | 000,100,908 | —- | C] () – C:\Users\Administrator\Desktop\SystemLook.exe
[2010/04/01 12:00:46 | 000,261,632 | —- | C] () – C:\WINDOWS\PEV.exe
[2010/04/01 12:00:46 | 000,098,816 | —- | C] () – C:\WINDOWS\sed.exe
[2010/04/01 12:00:46 | 000,080,412 | —- | C] () – C:\WINDOWS\grep.exe
[2010/04/01 12:00:46 | 000,077,312 | —- | C] () – C:\WINDOWS\MBR.exe
[2010/04/01 12:00:46 | 000,068,096 | —- | C] () – C:\WINDOWS\zip.exe
[2010/04/01 11:55:25 | 003,906,159 | R— | C] () – C:\Users\Administrator\Desktop\ComboFix.exe
[2010/03/31 14:17:28 | 000,293,376 | —- | C] () – C:\Users\Administrator\Desktop\eclzvb7p.exe
[2010/03/31 14:13:28 | 000,359,929 | —- | C] () – C:\Users\Administrator\Desktop\dds.scr
[2010/03/31 14:09:09 | 000,000,611 | —- | C] () – C:\Users\Administrator\Desktop\NTREGOPT.lnk
[2010/03/31 14:09:09 | 000,000,592 | —- | C] () – C:\Users\Administrator\Desktop\ERUNT.lnk
[2010/03/30 13:47:41 | 000,103,737 | —- | C] () – C:\Users\Administrator\Desktop\Eldest.htm
[2010/03/30 13:31:18 | 000,000,149 | —- | C] () – C:\Users\Administrator\Desktop\Butterflies (Blue Morpho or Cyrbia).url
[2010/03/30 13:03:54 | 000,678,623 | —- | C] () – C:\Users\Administrator\Desktop\Lizard!.jpg
[2010/03/30 12:59:28 | 000,365,359 | —- | C] () – C:\Users\Administrator\Desktop\Hearse.jpg
[2010/03/30 12:55:18 | 000,550,145 | —- | C] () – C:\Users\Administrator\Desktop\Lilies.jpg
[2010/03/26 18:21:18 | 000,000,552 | —- | C] () – C:\WINDOWS\System32\d3d8caps.dat
[2010/03/25 17:55:21 | 001,138,688 | —- | C] () – C:\Users\Administrator\Desktop\Memtest86_3.5.iso
[2010/03/24 22:26:31 | 000,000,696 | —- | C] () – C:\Users\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/03/24 20:31:08 | 000,001,707 | —- | C] () – C:\Users\All Users\Desktop\Avira AntiVir Control Center.lnk
[2010/03/24 17:27:32 | 000,001,657 | —- | C] () – C:\Users\All Users\Desktop\EverQuest.lnk
[2010/03/20 20:17:44 | 000,000,069 | —- | C] () – C:\WINDOWS\NeroDigital.ini
[2010/03/20 19:47:05 | 000,003,584 | —- | C] () – C:\Users\Administrator\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/03/20 19:28:48 | 000,377,344 | -HS- | C] () – C:\ehthumbs.db
[2010/03/20 19:19:38 | 000,000,000 | —- | C] () – C:\WINDOWS\nsreg.dat
[2010/03/08 00:57:57 | 000,000,754 | —- | C] () – C:\WINDOWS\WORDPAD.INI
[2010/03/02 23:00:45 | 000,009,094 | -HS- | C] () – C:\Users\Administrator\Local Settings\Application Data\6ENTSxRMA8c1v3wk4Gosy8f4p7
[2010/03/02 22:50:20 | 000,007,860 | -HS- | C] () – C:\Users\Administrator\Local Settings\Application Data\U4E5P2rdp
[2010/03/02 22:34:43 | 000,007,558 | -HS- | C] () – C:\Users\NetworkService\Local Settings\Application Data\U4E5P2rdp
[2010/02/18 18:49:36 | 000,000,119 | —- | C] () – C:\Users\Administrator\Local Settings\Application Data\fusioncache.dat
[2010/02/08 20:33:04 | 000,162,304 | —- | C] () – C:\WINDOWS\System32\ztvunrar36.dll
[2010/02/08 20:33:04 | 000,077,312 | —- | C] () – C:\WINDOWS\System32\ztvunace26.dll
[2010/02/08 20:26:00 | 000,057,344 | —- | C] () – C:\WINDOWS\System32\ff_vfw.dll
[2010/02/08 20:26:00 | 000,000,547 | —- | C] () – C:\WINDOWS\System32\ff_vfw.dll.manifest
[2009/03/23 19:38:02 | 001,481,728 | —- | C] () – C:\WINDOWS\System32\legitcheckcontrol.dll
[2009/01/18 12:22:56 | 000,001,008 | —- | C] () – C:\WINDOWS\System32\oeminfo.ini
[2008/10/07 10:13:30 | 000,197,912 | —- | C] () – C:\WINDOWS\System32\physxcudart_20.dll
[2008/10/07 10:13:22 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelTraditionalChinese.dll
[2008/10/07 10:13:20 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelSwedish.dll
[2008/10/07 10:13:20 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelSpanish.dll
[2008/10/07 10:13:20 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelSimplifiedChinese.dll
[2008/10/07 10:13:20 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelPortugese.dll
[2008/10/07 10:13:20 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelKorean.dll
[2008/10/07 10:13:20 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelJapanese.dll
[2008/10/07 10:13:20 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelGerman.dll
[2008/10/07 10:13:20 | 000,058,648 | —- | C] () – C:\WINDOWS\System32\AgCPanelFrench.dll
[2008/06/22 04:42:48 | 000,008,192 | —- | C] () – C:\WINDOWS\System32\vtthooks.dll
[2008/03/23 01:01:34 | 000,039,424 | —- | C] () – C:\WINDOWS\System32\vshellext.dll
[2008/03/23 01:00:10 | 000,040,960 | —- | C] () – C:\WINDOWS\System32\vclasses.dll
[2008/01/16 11:17:42 | 000,039,945 | —- | C] () – C:\WINDOWS\System32\winapp.ini
[2005/08/05 15:01:54 | 000,235,008 | —- | C] () – C:\WINDOWS\System32\psisdecd.dll
[2003/02/19 02:26:28 | 000,028,672 | —- | C] () – C:\WINDOWS\System32\cmirmdrv.dll

========== LOP Check ==========

[2010/03/25 17:16:05 | 000,000,000 | —D | M] – C:\Users\Administrator\Application Data\GARMIN
[2010/02/12 13:26:00 | 000,000,000 | —D | M] – C:\Users\Administrator\Application Data\OpenOffice.org
[2010/02/08 20:42:08 | 000,000,000 | —D | M] – C:\Users\Administrator\Application Data\OtakuSoftware
[2010/02/18 18:49:48 | 000,000,000 | —D | M] – C:\Users\Administrator\Application Data\Turbine

========== Purity Check ==========



========== Custom Scans ==========



< MD5 for: COMCTL32.DLL >
[2008/04/14 08:00:00 | 000,921,088 | R— | M] (Microsoft Corporation) MD5=AEF3D788DBF40C7C4D204EA45EB0C505 – C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.0.0_x-ww_1382d70a\comctl32.dll
[2008/04/14 08:00:00 | 001,054,208 | —- | M] (Microsoft Corporation) MD5=BD38D1EBE24A46BD3EDA059560AFBA12 – C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.5512_x-ww_35d4ce83\comctl32.dll
[2009/10/17 18:53:11 | 000,692,736 | —- | M] (Microsoft Corporation) MD5=C9FB1A9B3F9B51F08B665542DDFEE295 – C:\WINDOWS\system32\comctl32.dll

< MD5 for: EXPLORER.EXE >
[2009/10/17 18:53:14 | 001,697,280 | —- | M] (Microsoft Corporation) MD5=AEA58E2C358B987FCC612907377373C3 – C:\WINDOWS\explorer.exe

< MD5 for: SFCFILES.DLL >
[2009/10/17 18:35:04 | 001,614,848 | —- | M] (Microsoft Corporation) MD5=362BC5AF8EAF712832C58CC13AE05750 – C:\WINDOWS\system32\sfcfiles.dll

< MD5 for: TCPIP.SYS >
[2009/08/28 16:24:40 | 000,361,600 | —- | M] (Microsoft Corporation) MD5=F470A27484E43DA058BDFC235CD67FD1 – C:\WINDOWS\system32\drivers\tcpip.sys
[2009/08/28 16:24:40 | 000,361,600 | —- | M] (Microsoft Corporation) MD5=F470A27484E43DA058BDFC235CD67FD1 – C:\WINDOWS\system32\syscache\tcpip.sys

< MD5 for: TERMSRV.DLL >
[2009/09/11 08:23:47 | 000,295,424 | —- | M] (Microsoft Corporation) MD5=EE87B66DBB4D5C44E94854118664EF42 – C:\WINDOWS\system32\syscache\termsrv.dll
[2009/09/11 08:23:47 | 000,295,424 | —- | M] (Microsoft Corporation) MD5=EE87B66DBB4D5C44E94854118664EF42 – C:\WINDOWS\system32\termsrv.dll

< MD5 for: USER32.DLL >
[2009/10/17 18:53:38 | 000,578,048 | —- | M] (Microsoft Corporation) MD5=6616894470538493B9AAE74271F099EF – C:\WINDOWS\system32\user32.dll
< End of report >


EXTRAS.txt follows:
OTL Extras logfile created on: 4/1/2010 10:31:59 PM - Run 1
OTL by OldTimer - Version 3.1.37.3 Folder = C:\Users\Administrator\Desktop
Windows XP Media Center Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1,022.00 Mb Total Physical Memory | 698.00 Mb Available Physical Memory | 68.00% Memory free
2.00 Gb Paging File | 2.00 Gb Available in Paging File | 84.00% Paging File free
Paging file location(s): C:\pagefile.sys 1533 2500 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 37.24 Gb Total Space | 20.14 Gb Free Space | 54.09% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: ANY-B33CA27F5BF
Current User Name: Administrator
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: On
Skip Microsoft Files: On
File Age = 14 Days
Output = Minimal
Quick Scan

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.exe [@ = secfile] – Reg Error: Key error. File not found
.html [@ = Reg Error: Value error.] – Reg Error: Key error. File not found

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.exe [@ = exefile] – Reg Error: Key error. File not found
.html [@ = FirefoxHTML] – C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
htmlfile – Reg Error: Key error.
https [open] – "C:\Program Files\Firefox\firefox.exe" -requestPending -osint -url "%1" File not found
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusOverride" = 1
"FirewallOverride" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 0
"DoNotAllowExceptions" = 0
"DisableNotifications" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 0
"DoNotAllowExceptions" = 0
"DisableNotifications" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\Sony\Station\LaunchPad\LaunchPad.exe" = C:\Program Files\Sony\Station\LaunchPad\LaunchPad.exe:*:Enabled:LaunchPad – ()


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{139E303E-1050-497F-98B1-9AE87B15C463}" = Windows Live Family Safety
"{15F4085A-BC98-4590-AFFD-03BBBE49524E}" = Garmin Communicator Plugin
"{178832DE-9DE0-4C87-9F82-9315A9B03985}" = Windows Live Writer
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{26A24AE4-039D-4CA4-87B4-2F83216016FF}" = Java™ 6 Update 16
"{2E376AD9-5C49-4F7D-A0BA-6A44E8FA5A3B}" = Next Generation Visualisations
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{3921A67A-5AB1-4E48-9444-C71814CF3027}" = VCRedistSetup
"{3B4E636E-9D65-4D67-BA61-189800823F52}" = Windows Live Communications Platform
"{3F3733A5-8322-454D-A638-3B74E1C83752}" = Gadget Installer
"{45338B07-A236-4270-9A77-EBB4115517B5}" = Windows Live Sign-in Assistant
"{4CBA3D4C-8F51-4D60-B27E-F6B641C571E7}" = Microsoft Search Enhancement Pack
"{56C049BE-79E9-4502-BEA7-9754A3E60F9B}" = neroxml
"{6412CECE-8172-4BE5-935B-6CECACD2CA87}" = Windows Live Mail
"{65F9E1F3-A2C1-4AA9-9F33-A3AEB0255F0E}" = Garmin USB Drivers
"{81128EE8-8EAD-4DB0-85C6-17C2CE50FF71}" = Windows Live Essentials
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8A708DD8-A5E6-11D4-A706-000629E95E20}" = Intel® Extreme Graphics Driver
"{8A74E887-8F0F-4017-AF53-CBA42211AAA5}" = Microsoft Sync Framework Runtime Native v1.0 (x86)
"{995F1E2E-F542-4310-8E1D-9926F5A279B3}" = Windows Live Toolbar
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{A007D3BA-1C94-4286-A0F7-507417495DF7}" = EverQuest Platinum
"{A1F66FC9-11EE-4F2F-98C9-16F8D1E69FB7}" = Segoe UI
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A49F249F-0C91-497F-86DF-B2585E8E76B7}" = Microsoft Visual C++ 2005 Redistributable
"{A85FD55B-891B-4314-97A5-EA96C0BD80B5}" = Windows Live Messenger
"{AC76BA86-7AD7-1033-7B44-A91000000001}" = Adobe Reader 9.1
"{B43357AA-3A6D-4D94-B56E-43C44D09E548}" = Microsoft .NET Framework (English)
"{BB05D173-9681-4812-A7FA-BD4042A3DA00}" = Alky for Applications (Windows XP)
"{BD64AF4A-8C80-4152-AD77-FCDDF05208AB}" = Microsoft Sync Framework Services Native v1.0 (x86)
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D6C75F0B-3BC1-4FC9-B8C5-3F7E8ED059CA}" = Windows Live Photo Gallery
"{D6C9AF27-9414-46C8-B9D8-D878BA041033}" = Nero 8
"{DD1865F0-AD73-40FB-B23E-1822E02396FF}" = NVIDIA PhysX
"{E2DFE069-083E-4631-9B6C-43C48E991DE5}" = Junk Mail filter update
"{E6B87DC4-2B3D-4483-ADFF-E483BF718991}" = OpenOffice.org 3.1
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard
"49CF605F02C7954F4E139D18828DE298CD59217C" = Windows Driver Package - Garmin (grmnusb) GARMIN Devices (06/03/2009 2.3.0.0)
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Avira AntiVir Desktop" = Avira AntiVir Personal - Free Antivirus
"C-Media Audio Driver" = C-Media WDM Audio Driver
"ERUNT_is1" = ERUNT 1.1j
"ie8" = Windows Internet Explorer 8
"Installing HSP56 MicroModem Drivers" = HSP56 Modem Drivers
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Mozilla Firefox (3.6.2)" = Mozilla Firefox (3.6.2)
"NVIDIA Drivers" = NVIDIA Drivers
"NVIDIA nView Desktop Manager" = NVIDIA nView Desktop Manager
"Revo Uninstaller" = Revo Uninstaller 1.85
"SiSLan" = SiS 900 PCI Fast Ethernet Adapter Driver
"WinRAR archiver" = WinRAR archiver
"XpsEPSC" = XML Paper Specification Shared Components Pack 1.0

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 3/2/2010 11:16:18 PM | Computer Name = ANY-B33CA27F5BF | Source = Application Error | ID = 1000
Description = Faulting application ffk.exe, version 6.5.65.38, faulting module ffk.exe,
version 6.5.65.38, fault address 0x0000682d.

Error - 3/2/2010 11:21:13 PM | Computer Name = ANY-B33CA27F5BF | Source = Application Error | ID = 1000
Description = Faulting application ffk.exe, version 6.5.65.38, faulting module ffk.exe,
version 6.5.65.38, fault address 0x0000682d.

Error - 3/4/2010 4:36:10 AM | Computer Name = ANY-B33CA27F5BF | Source = Application Error | ID = 1000
Description = Faulting application chrome.exe, version 0.0.0.0, faulting module
chrome.dll, version 4.0.249.89, fault address 0x006a4188.

[ System Events ]
Error - 3/30/2010 1:02:28 PM | Computer Name = ANY-B33CA27F5BF | Source = Disk | ID = 262151
Description = The device, \Device\Harddisk1\D, has a bad block.

Error - 3/30/2010 1:02:47 PM | Computer Name = ANY-B33CA27F5BF | Source = Disk | ID = 262155
Description = The driver detected a controller error on \Device\Harddisk1\D.

Error - 3/30/2010 8:28:11 PM | Computer Name = ANY-B33CA27F5BF | Source = Ftdisk | ID = 262189
Description = The system could not sucessfully load the crash dump driver.

Error - 3/30/2010 8:28:11 PM | Computer Name = ANY-B33CA27F5BF | Source = Ftdisk | ID = 262193
Description = Configuring the Page file for crash dump failed. Make sure there is
a page file on the boot partition and that is large enough to contain all physical
memory.

Error - 3/31/2010 1:28:34 PM | Computer Name = ANY-B33CA27F5BF | Source = Ftdisk | ID = 262189
Description = The system could not sucessfully load the crash dump driver.

Error - 3/31/2010 1:28:34 PM | Computer Name = ANY-B33CA27F5BF | Source = Ftdisk | ID = 262193
Description = Configuring the Page file for crash dump failed. Make sure there is
a page file on the boot partition and that is large enough to contain all physical
memory.

Error - 3/31/2010 8:15:22 PM | Computer Name = ANY-B33CA27F5BF | Source = Ftdisk | ID = 262189
Description = The system could not sucessfully load the crash dump driver.

Error - 3/31/2010 8:15:22 PM | Computer Name = ANY-B33CA27F5BF | Source = Ftdisk | ID = 262193
Description = Configuring the Page file for crash dump failed. Make sure there is
a page file on the boot partition and that is large enough to contain all physical
memory.

Error - 4/1/2010 11:06:54 AM | Computer Name = ANY-B33CA27F5BF | Source = Ftdisk | ID = 262189
Description = The system could not sucessfully load the crash dump driver.

Error - 4/1/2010 11:06:54 AM | Computer Name = ANY-B33CA27F5BF | Source = Ftdisk | ID = 262193
Description = Configuring the Page file for crash dump failed. Make sure there is
a page file on the boot partition and that is large enough to contain all physical
memory.


< End of report >
Hi Trilo, There are no usable replacements for those file on your system. Do you have a Windows XP install CD or can you borrow one from a friend (It has to be a Windows XP Media Center Edition Service Pack 3 disk)?
We will be able to borrow a copy, however it may be a few days before we can travel to get it. I understand that threads normally get locked after 3 days of inactivity, yet I cannot guarantee that I will have it by then. Even so, we are only talking about a few days anyway, so it will be close to that timeframe. What will be your instructions, once we get it?
As long as I know you are still working with me, I'll leave the thread open. I'll post the instructions shortly - I wanted to make sure you could get a disk before I prepared them.
You're welcome Trilo. Here are your instructions. Please go over them completely and let me know if you have any questions before you start:

🖼Click to load external image (Posted Image) Insert the Windows XP installation disk.

1. ClickStart > Run or press the Windows Key + R Then type cmd in the run box and press "OK" to open the command prompt window

2. Enter the following commands, one at a time, at the prompt and press "Enter" after each one. Refer to the quote box under the commands for the location of the spaces which are very important. After pressing "Enter" you should see a message that says, "one file(s) expanded successfully"

Note: x = the drive letter designation for your CD/DVD drive - replace x with the appropriate letter for your PC (usually D:\ or E:\).

expand x:\i386\comctl32.dl_ -r c:\windows\system32

expand x:\i386\user32.dl_ -r c:\windows\system32

expand x:\i386\sfcfiles.dl_ -r c:\windows\system32

expand x:\i386\termsrv.dl_ -r c:\windows\system32

expand x:\i386\explorer.ex_ c:\windows


expandx:\i386\comctl32.dl_-rc:\windows\system32

expandx:\i386\user32.dl_-rc:\windows\system32

expandx:\i386\sfcfiles.dl_-rc:\windows\system32

expandx:\i386\termsrv.dl_-rc:\windows\system32

expandx:\i386\explorer.ex_c:\windows


Please include the following in your next post:
  • Let me know how this went

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI