This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] just-in-time debugging window keeps popping up

15 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I'm running XP and I'm using Microsoft Security Essentials which keeps coming up red and deleating files out of win32, and I keep getting a Jut-In-Time- Debugger window popping up at various times.

Attach.txt:

DDS (Ver_09-06-26.01)

Microsoft Windows XP Professional
Boot Device: \Device\HarddiskVolume2
Install Date: 9/26/2006 9:47:02 AM
System Uptime: 5/1/2010 11:29:15 AM (1 hours ago)

Motherboard: Dell Computer Corp. | | 0WF887
Processor: Intel® Celeron® CPU 2.53GHz | Microprocessor | 2527/533mhz

==== Disk Partitions =========================

C: is FIXED (NTFS) - 109 GiB total, 91.125 GiB free.
D: is FIXED (NTFS) - 37 GiB total, 36.903 GiB free.
E: is CDROM ()
F: is FIXED (NTFS) - 75 GiB total, 23.796 GiB free.

==== Disabled Device Manager Items =============

Class GUID: {4D36E972-E325-11CE-BFC1-08002BE10318}
Description: Linksys Wireless-G PCI Adapter
Device ID: PCI\VEN_1814&DEV_0301&SUBSYS_00551737&REV_00\4&1C660DD6&0&10F0
Manufacturer: Linksys, A Division of Cisco Systems, Inc.
Name: Linksys Wireless-G PCI Adapter
PNP Device ID: PCI\VEN_1814&DEV_0301&SUBSYS_00551737&REV_00\4&1C660DD6&0&10F0
Service: RT61

==== System Restore Points ===================

RP95: 4/27/2010 6:04:41 PM - System Checkpoint
RP96: 4/29/2010 9:11:26 PM - System Checkpoint
RP97: 5/1/2010 11:53:57 AM - Software Distribution Service 3.0
RP98: 5/1/2010 12:23:17 PM - Automatic Restore Point

==== Installed Programs ======================


2FlyerPro
Acrobat.com
Ad-Aware
Adobe AIR
Adobe Flash Player 10 ActiveX
Adobe Flash Player 10 Plugin
Adobe Reader 9.3
Adobe Shockwave Player
Adobe SVG Viewer 3.0
AnswerWorks 5.0 English Runtime
AOLIcon
ArcSoft PhotoBase 3
ArcSoft PhotoStudio 5
AVI Movie Player
AXIS Media Control
AXIS Media Control Embedded
CA Licensing
Canon CanoScan Toolbox 4.1
CCleaner (remove only)
CD LabelMaker 5
Compatibility Pack for the 2007 Office system
ConvertXtoDVD 2.2.3.258
Corel Photo Album 6
Critical Update for Windows Media Player 11 (KB959772)
Dell CinePlayer
Dell Digital Jukebox Driver
Dell Driver Reset Tool
Dell Laser MFP 1815 Software Uninstall
Dell Printer Software Uninstall
Dell System Restore
Digital Content Portal
ERUNT 1.1j
Hotfix 2050 for SQL Server 2000 ENU (KB948110)
Hotfix 2055 for SQL Server 2000 ENU (KB960082)
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
Hotfix for Windows Media Format 11 SDK (KB929399)
Hotfix for Windows Media Player 11 (KB939683)
Hotfix for Windows XP (KB952287)
Hotfix for Windows XP (KB954550-v5)
Hotfix for Windows XP (KB961118)
Hotfix for Windows XP (KB970653-v3)
Hotfix for Windows XP (KB976098-v2)
Hotfix for Windows XP (KB979306)
hp deskjet 840c series (Remove only)
HP Product Detection
ICQ6.5
Intel® Extreme Graphics 2 Driver
Intel® PRO Network Adapters and Drivers
Intel® PROSet for Wired Connections
Internet RadioFan 1.3.0
J2SE Runtime Environment 5.0 Update 6
Java™ 6 Update 17
Java™ 6 Update 7
Learn2 Player (Uninstall Only)
LimeWire 4.18.8
MailWasher Free 6.5.2
Malwarebytes' Anti-Malware
MCU
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Security Update (KB953297)
Microsoft .NET Framework 2.0 Service Pack 2
Microsoft .NET Framework 3.0 Service Pack 2
Microsoft .NET Framework 3.5 SP1
Microsoft Antimalware
Microsoft Application Error Reporting
Microsoft Compression Client Pack 1.0 for Windows XP
Microsoft Internationalized Domain Names Mitigation APIs
Microsoft National Language Support Downlevel APIs
Microsoft Office 2007 Service Pack 2 (SP2)
Microsoft Office Access MUI (English) 2007
Microsoft Office Access Setup Metadata MUI (English) 2007
Microsoft Office Excel MUI (English) 2007
Microsoft Office InfoPath MUI (English) 2007
Microsoft Office Outlook MUI (English) 2007
Microsoft Office PowerPoint MUI (English) 2007
Microsoft Office PowerPoint Viewer 2003
Microsoft Office Professional Plus 2007
Microsoft Office Proof (English) 2007
Microsoft Office Proof (French) 2007
Microsoft Office Proof (Spanish) 2007
Microsoft Office Proofing (English) 2007
Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
Microsoft Office Publisher MUI (English) 2007
Microsoft Office Shared MUI (English) 2007
Microsoft Office Shared Setup Metadata MUI (English) 2007
Microsoft Office Word MUI (English) 2007
Microsoft Plus! Digital Media Edition Installer
Microsoft Plus! Photo Story 2 LE
Microsoft Security Essentials
Microsoft Silverlight
Microsoft Software Update for Web Folders (English) 12
Microsoft SQL Server Desktop Engine (MICROSOFTSMLBIZ)
Microsoft User-Mode Driver Framework Feature Pack 1.0
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
Mozilla Firefox (3.0.18)
MRU-Blaster v1.5 (Database 3/28/2004)
MSN
MSXML 4.0 SP2 (KB927978)
MSXML 4.0 SP2 (KB936181)
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 (KB973688)
NoteTab Light 5 (Remove only)
OGA Notifier 2.0.0048.0
OmniPage SE
OpenOffice.org Installer 1.0
Photo Viewer
PrimoPDF
PSP Thumbnail Handler
Qualxserve Service Agreement
QuickTime
RealPlayer Basic
Roxio DLA
Roxio MyDVD LE
Roxio RecordNow Audio
Roxio RecordNow Copy
Roxio RecordNow Data
SBA
ScrewDrivers Client v3
Seagate Manager Installer
SearchAssist
Security Update for 2007 Microsoft Office System (KB969559)
Security Update for 2007 Microsoft Office System (KB978380)
Security Update for CAPICOM (KB931906)
Security Update for Microsoft Office Excel 2007 (KB978382)
Security Update for Microsoft Office Outlook 2007 (KB972363)
Security Update for Microsoft Office PowerPoint 2007 (KB957789)
Security Update for Microsoft Office Publisher 2007 (KB980470)
Security Update for Microsoft Office system 2007 (972581)
Security Update for Microsoft Office system 2007 (KB969613)
Security Update for Microsoft Office system 2007 (KB974234)
Security Update for Microsoft Office Visio Viewer 2007 (KB973709)
Security Update for Microsoft Office Word 2007 (KB969604)
Security Update for Step By Step Interactive Training (KB898458)
Security Update for Step By Step Interactive Training (KB923723)
Security Update for Windows Internet Explorer 7 (KB938127)
Security Update for Windows Internet Explorer 7 (KB950759)
Security Update for Windows Internet Explorer 7 (KB953838)
Security Update for Windows Internet Explorer 7 (KB956390)
Security Update for Windows Internet Explorer 7 (KB958215)
Security Update for Windows Internet Explorer 7 (KB960714)
Security Update for Windows Internet Explorer 7 (KB961260)
Security Update for Windows Internet Explorer 7 (KB963027)
Security Update for Windows Internet Explorer 7 (KB969897)
Security Update for Windows Internet Explorer 7 (KB972260)
Security Update for Windows Internet Explorer 7 (KB974455)
Security Update for Windows Internet Explorer 7 (KB976325)
Security Update for Windows Internet Explorer 7 (KB978207)
Security Update for Windows Media Player (KB911564)
Security Update for Windows Media Player (KB952069)
Security Update for Windows Media Player (KB954155)
Security Update for Windows Media Player (KB968816)
Security Update for Windows Media Player (KB973540)
Security Update for Windows Media Player 10 (KB917734)
Security Update for Windows Media Player 10 (KB936782)
Security Update for Windows Media Player 11 (KB936782)
Security Update for Windows Media Player 11 (KB954154)
Security Update for Windows Media Player 6.4 (KB925398)
Security Update for Windows XP (KB923561)
Security Update for Windows XP (KB923689)
Security Update for Windows XP (KB938464-v2)
Security Update for Windows XP (KB938464)
Security Update for Windows XP (KB941569)
Security Update for Windows XP (KB946648)
Security Update for Windows XP (KB950759)
Security Update for Windows XP (KB950760)
Security Update for Windows XP (KB950762)
Security Update for Windows XP (KB950974)
Security Update for Windows XP (KB951066)
Security Update for Windows XP (KB951376-v2)
Security Update for Windows XP (KB951698)
Security Update for Windows XP (KB951748)
Security Update for Windows XP (KB952004)
Security Update for Windows XP (KB952954)
Security Update for Windows XP (KB953839)
Security Update for Windows XP (KB954211)
Security Update for Windows XP (KB954459)
Security Update for Windows XP (KB954600)
Security Update for Windows XP (KB955069)
Security Update for Windows XP (KB956391)
Security Update for Windows XP (KB956572)
Security Update for Windows XP (KB956744)
Security Update for Windows XP (KB956802)
Security Update for Windows XP (KB956803)
Security Update for Windows XP (KB956841)
Security Update for Windows XP (KB956844)
Security Update for Windows XP (KB957095)
Security Update for Windows XP (KB957097)
Security Update for Windows XP (KB958644)
Security Update for Windows XP (KB958687)
Security Update for Windows XP (KB958690)
Security Update for Windows XP (KB958869)
Security Update for Windows XP (KB959426)
Security Update for Windows XP (KB960225)
Security Update for Windows XP (KB960715)
Security Update for Windows XP (KB960803)
Security Update for Windows XP (KB960859)
Security Update for Windows XP (KB961371)
Security Update for Windows XP (KB961373)
Security Update for Windows XP (KB961501)
Security Update for Windows XP (KB968537)
Security Update for Windows XP (KB969059)
Security Update for Windows XP (KB969898)
Security Update for Windows XP (KB969947)
Security Update for Windows XP (KB970238)
Security Update for Windows XP (KB970430)
Security Update for Windows XP (KB971468)
Security Update for Windows XP (KB971486)
Security Update for Windows XP (KB971557)
Security Update for Windows XP (KB971633)
Security Update for Windows XP (KB971657)
Security Update for Windows XP (KB971961)
Security Update for Windows XP (KB972270)
Security Update for Windows XP (KB973346)
Security Update for Windows XP (KB973354)
Security Update for Windows XP (KB973507)
Security Update for Windows XP (KB973525)
Security Update for Windows XP (KB973869)
Security Update for Windows XP (KB973904)
Security Update for Windows XP (KB974112)
Security Update for Windows XP (KB974318)
Security Update for Windows XP (KB974392)
Security Update for Windows XP (KB974571)
Security Update for Windows XP (KB975025)
Security Update for Windows XP (KB975467)
Security Update for Windows XP (KB975560)
Security Update for Windows XP (KB975561)
Security Update for Windows XP (KB975713)
Security Update for Windows XP (KB977165)
Security Update for Windows XP (KB977816)
Security Update for Windows XP (KB977914)
Security Update for Windows XP (KB978037)
Security Update for Windows XP (KB978251)
Security Update for Windows XP (KB978262)
Security Update for Windows XP (KB978338)
Security Update for Windows XP (KB978601)
Security Update for Windows XP (KB978706)
Security Update for Windows XP (KB979309)
Security Update for Windows XP (KB979683)
Security Update for Windows XP (KB980232)
Security Update for Windows XP (KB981349)
Solitaire
Sonic Activation Module
Sonic Update Manager
Spybot - Search & Destroy
Templates for Today's Time-Crunched Professional
TurboTax 2008
TurboTax 2008 wiliper
TurboTax 2008 WinPerFedFormset
TurboTax 2008 WinPerProgramHelp
TurboTax 2008 WinPerReleaseEngine
TurboTax 2008 WinPerTaxSupport
TurboTax 2008 WinPerUserEducation
TurboTax 2008 wrapper
Update for 2007 Microsoft Office System (KB967642)
Update for 2007 Microsoft Office System (KB981715)
Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
Update for Microsoft Office InfoPath 2007 (KB976416)
Update for Outlook 2007 Junk Email Filter (kb981433)
Update for Windows Internet Explorer 7 (KB976749)
Update for Windows Internet Explorer 7 (KB980182)
Update for Windows XP (KB942763)
Update for Windows XP (KB951072-v2)
Update for Windows XP (KB951978)
Update for Windows XP (KB955759)
Update for Windows XP (KB955839)
Update for Windows XP (KB967715)
Update for Windows XP (KB968389)
Update for Windows XP (KB971737)
Update for Windows XP (KB973687)
Update for Windows XP (KB973815)
URL Assistant
Viewpoint Media Player
WebFldrs XP
Windows Driver Package - (mr7910) Image (08/08/2006 1.4.0.0)
Windows Genuine Advantage Notifications (KB905474)
Windows Genuine Advantage Validation Tool (KB892130)
Windows Installer 3.1 (KB893803)
Windows Internet Explorer 7
Windows Media Format 11 runtime
Windows Media Player 10
Windows Media Player 11
Windows XP Service Pack 3
WinRAR archiver
WinZip 12.0
Yahoo! Toolbar

==== Event Viewer Messages From Past Week ========

4/29/2010 6:53:40 PM, error: Microsoft Antimalware [2001] - Microsoft Antimalware has encountered an error trying to update signatures. New Signature Version: Previous Signature Version: 1.81.236.0 Update Source: Microsoft Update Server Update Stage: Search Source Path: http://www.microsoft.com Signature Type: AntiVirus Update Type: Full User: NT AUTHORITY\SYSTEM Current Engine Version: Previous Engine Version: 1.1.5605.0 Error code: 0x80072efe Error description: The connection with the server was terminated abnormally
4/28/2010 10:02:20 AM, error: Microsoft Antimalware [2001] - Microsoft Antimalware has encountered an error trying to update signatures. New Signature Version: Previous Signature Version: 1.81.236.0 Update Source: Microsoft Update Server Update Stage: Search Source Path: http://www.microsoft.com Signature Type: AntiVirus Update Type: Full User: NT AUTHORITY\SYSTEM Current Engine Version: Previous Engine Version: 1.1.5605.0 Error code: 0x80072efe Error description: The connection with the server was terminated abnormally
4/27/2010 6:27:41 PM, error: Service Control Manager [7034] - The Machine Debug Manager service terminated unexpectedly. It has done this 1 time(s).
4/26/2010 7:16:57 PM, error: Service Control Manager [7032] - The Service Control Manager tried to take a corrective action (Restart the service) after the unexpected termination of the Microsoft Antimalware Service service, but this action failed with the following error: An instance of the service is already running.
4/26/2010 7:16:42 PM, error: Service Control Manager [7031] - The Microsoft Antimalware Service service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 15000 milliseconds: Restart the service.
4/26/2010 6:02:06 PM, error: Microsoft Antimalware [2001] - Microsoft Antimalware has encountered an error trying to update signatures. New Signature Version: Previous Signature Version: 1.81.236.0 Update Source: Microsoft Update Server Update Stage: Search Source Path: http://www.microsoft.com Signature Type: AntiVirus Update Type: Full User: NT AUTHORITY\SYSTEM Current Engine Version: Previous Engine Version: 1.1.5605.0 Error code: 0x80072efe Error description: The connection with the server was terminated abnormally
4/25/2010 8:59:41 PM, error: BROWSER [8007] - The browser was unable to update the service status bits. The data is the error.
4/25/2010 4:24:35 PM, error: Service Control Manager [7011] - Timeout (30000 milliseconds) waiting for a transaction response from the WZCSVC service.
4/25/2010 3:12:14 PM, error: Service Control Manager [7001] - The Print Spooler service depends on the LexBce Server service which failed to start because of the following error: The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.
4/25/2010 3:12:14 PM, error: Service Control Manager [7001] - The Fax service depends on the Print Spooler service which failed to start because of the following error: The dependency service or group failed to start.
4/25/2010 2:58:51 PM, error: Microsoft Antimalware [2001] - Microsoft Antimalware has encountered an error trying to update signatures. New Signature Version: Previous Signature Version: 1.81.236.0 Update Source: Microsoft Update Server Update Stage: Search Source Path: http://www.microsoft.com Signature Type: AntiVirus Update Type: Full User: NT AUTHORITY\SYSTEM Current Engine Version: Previous Engine Version: 1.1.5605.0 Error code: 0x80072efe Error description: The connection with the server was terminated abnormally
4/25/2010 2:53:32 PM, error: Microsoft Antimalware [2001] - Microsoft Antimalware has encountered an error trying to update signatures. New Signature Version: Previous Signature Version: 1.81.236.0 Update Source: Microsoft Update Server Update Stage: Search Source Path: http://www.microsoft.com Signature Type: AntiVirus Update Type: Full User: NT AUTHORITY\SYSTEM Current Engine Version: Previous Engine Version: 1.1.5605.0 Error code: 0x80072efe Error description: The connection with the server was terminated abnormally
4/25/2010 2:36:16 PM, error: Microsoft Antimalware [2004] - Microsoft Antimalware has encountered an error trying to load signatures and will attempt reverting back to a known-good set of signatures. Signatures Attempted: Current Error Code: 0x80070002 Error description: The system cannot find the file specified. Signature version: 0.0.0.0;0.0.0.0 Engine version: 0.0.0.0
4/24/2010 8:38:53 PM, error: Microsoft Antimalware [1008] - Microsoft Antimalware has encountered an error when taking action on spyware or other potentially unwanted software. For more information please see the following: http://go.microsoft.com/fwlink/?linkid=370…atid=2147581187 User: NT AUTHORITY\SYSTEM Name: Backdoor:Win32/Nuwar.A ID: 2147581187 Severity: Severe Category: Backdoor Path: Action: Quarantine Error Code: 0x80508023 Error description: The program could not find the spyware and other potentially unwanted software on this computer. Status: Signature Version: AV: 1.81.366.0, AS: 1.81.366.0 Engine Version: 1.1.5703.0
4/24/2010 8:21:07 PM, error: Ftdisk [49] - Configuring the Page file for crash dump failed. Make sure there is a page file on the boot partition and that is large enough to contain all physical memory.
4/24/2010 8:21:07 PM, error: Ftdisk [45] - The system could not sucessfully load the crash dump driver.
4/24/2010 8:18:20 PM, error: Microsoft Antimalware [1008] - Microsoft Antimalware has encountered an error when taking action on spyware or other potentially unwanted software. For more information please see the following: http://go.microsoft.com/fwlink/?linkid=370…atid=2147581187 User: GEORGE\admin Name: Backdoor:Win32/Nuwar.A ID: 2147581187 Severity: Severe Category: Backdoor Path: Action: Quarantine Error Code: 0x80508023 Error description: The program could not find the spyware and other potentially unwanted software on this computer. Status: Signature Version: AV: 1.81.236.0, AS: 1.81.236.0 Engine Version: 1.1.5703.0

==== End Of File ===========================
DDS.txt:
DDS (Ver_09-06-26.01) - NTFSx86
Run by [removed] at 12:34:40.56 on Sat 05/01/2010
Internet Explorer: 7.0.5730.13 BrowserJavaVersion: 1.6.0_17
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.510.189 [GMT -5:00]

AV: Microsoft Security Essentials *On-access scanning enabled* (Updated) {BCF43643-A118-4432-AEDE-D861FCBCFCDF}
AV: Symantec AntiVirus Corporate Edition *On-access scanning disabled* (Outdated) {FB06448E-52B8-493A-90F3-E43226D3305C}

============== Running Processes ===============

C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
c:\Program Files\Microsoft Security Essentials\MsMpEng.exe
C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup
C:\WINDOWS\system32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\DLA\DLACTRLW.EXE
C:\Program Files\Microsoft Security Essentials\msseces.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
svchost.exe
C:\Program Files\CA\SharedComponents\CA_LIC\LogWatNT.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTSMLBIZ\Binn\sqlservr.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\admin\Desktop\what the tech\dds.scr

============== Pseudo HJT Report ===============

uStart Page = about:blank
uSearch Page = hxxp://us.rd.yahoo.com/customize/ie/defaults/sp/msgr9/*http://www.yahoo.com
uSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr9/*http://www.yahoo.com/ext/search/search.html
uDefault_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk&channel=us&ibd=5060919
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr9/*http://www.yahoo.com/ext/search/search.html
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ie/defaults/su/msgr9/*http://www.yahoo.com
mSearchAssistant = hxxp://www.google.com/hws/sb/dell-usuk/en/side.html?channel=us
uURLSearchHooks: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn\yt.dll
BHO: Yahoo! Toolbar Helper: {02478d38-c3f9-4efb-9b51-7695eca05670} - c:\program files\yahoo!\companion\installs\cpn\yt.dll
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: CBrowserHelperObject Object: {ca6319c0-31b7-401e-a518-a07c3db8f777} - c:\program files\bae\BAE.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn\yt.dll
TB: {472734EA-242A-422B-ADF8-83D1E48CC825} - No File
EB: Real.com: {fe54fa40-d68c-11d2-98fa-00c0f0318afe} - c:\windows\system32\Shdocvw.dll
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
mRun: [DLA] c:\windows\system32\dla\DLACTRLW.EXE
mRun: [MSSE] "c:\program files\microsoft security essentials\msseces.exe" -hide -runkey
mRun: [Malwarebytes Anti-Malware (reboot)] "c:\program files\malwarebytes' anti-malware\mbam.exe" /runcleanupscript
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {E59EB121-F339-4851-A3BA-FE49C35617C2} - c:\program files\icq6.5\ICQ.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL
IE: {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - {FE54FA40-D68C-11d2-98FA-00C0F0318AFE} - c:\windows\system32\Shdocvw.dll
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1159284260343
DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} - hxxps://h20436.www2.hp.com/ediags/dex/secure/HPDEXAXO.cab
DPF: {73ECB3AA-4717-450C-A2AB-D00DAD9EE203} - hxxp://h20270.www2.hp.com/ediags/gmn2/install/HPProductDetection2.cab
DPF: {745395C8-D0E1-4227-8586-624CA9A10A8D} - hxxp://camera6.buffalotrace.com/activex/AMC.cab
DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - hxxp://download.eset.com/special/eos/OnlineScanner.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
DPF: {917623D1-D8E5-11D2-BE8B-00104B06BDE3} - hxxp://cam2.asa.utk.edu/activex/AxisCamControl.cab
DPF: {C111A91F-D4EC-4D22-8D27-C3BCB0389F43} - hxxp://www.boydsnest-ti.com/activex/AMC.cab
DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_06-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
DPF: {DE625294-70E6-45ED-B895-CFFA13AEB044} - hxxp://205.241.135.70/activex/AMC.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
Notify: igfxcui - igfxdev.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll

================= FIREFOX ===================

FF - ProfilePath - c:\docume~1\admin\applic~1\mozilla\firefox\profiles\arkm7om1.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/
FF - plugin: c:\program files\viewpoint\viewpoint experience technology\npViewpoint.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0010-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0012-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}

============= SERVICES / DRIVERS ===============

R2 aawservice;Lavasoft Ad-Aware Service;c:\program files\lavasoft\ad-aware\aawservice.exe [2008-9-10 611664]
R2 LogWatch;Event Log Watch;c:\program files\ca\sharedcomponents\ca_lic\LogWatNT.exe [2002-9-20 53248]
S1 MpKsl0f135ce1;MpKsl0f135ce1;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{4669ef94-ab70-4e78-b64a-8e1f26187fe3}\mpksl0f135ce1.sys –> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{4669ef94-ab70-4e78-b64a-8e1f26187fe3}\MpKsl0f135ce1.sys [?]
S1 MpKsl4894e515;MpKsl4894e515;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{4669ef94-ab70-4e78-b64a-8e1f26187fe3}\mpksl4894e515.sys –> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{4669ef94-ab70-4e78-b64a-8e1f26187fe3}\MpKsl4894e515.sys [?]
S3 CA_LIC_CLNT;CA License Client;c:\program files\ca\sharedcomponents\ca_lic\lic98rmt.exe [2002-9-20 77824]
S3 CA_LIC_SRVR;CA License Server;c:\program files\ca\sharedcomponents\ca_lic\lic98rmtd.exe [2002-9-20 77824]
S3 NAVENG;NAVENG;\??\c:\progra~1\common~1\symant~1\virusd~1\20080825.020\naveng.sys –> c:\progra~1\common~1\symant~1\virusd~1\20080825.020\naveng.sys [?]
S3 NAVEX15;NAVEX15;\??\c:\progra~1\common~1\symant~1\virusd~1\20080825.020\navex15.sys –> c:\progra~1\common~1\symant~1\virusd~1\20080825.020\navex15.sys [?]
S4 FreeAgentGoNext Service;Seagate Service;c:\program files\seagate\seagatemanager\sync\FreeAgentService.exe [2009-1-16 161064]
S4 IntuitUpdateService;Intuit Update Service;c:\program files\common files\intuit\update service\IntuitUpdateService.exe [2008-12-9 13088]

=============== Created Last 30 ================

2010-04-30 18:04 96,512 a——- c:\windows\system32\drivers\hsiwouul.sys
2010-04-29 21:44 96,512 a——- c:\windows\system32\drivers\ATAPI.SYS
2010-04-27 17:45 664 a——- c:\windows\system32\d3d9caps.dat
2010-04-27 17:45 552 a——- c:\windows\system32\d3d8caps.dat
2010-04-25 14:35 –d—– c:\windows\system32\wbem\Repository

==================== Find3M ====================

2010-03-10 08:18 13,824 ——– c:\windows\system32\dllcache\ieudinit.exe
2010-03-10 08:18 70,656 ——– c:\windows\system32\dllcache\ie4uinit.exe
2010-03-09 06:09 430,080 a——- c:\windows\system32\vbscript.dll
2010-03-09 06:09 430,080 ——– c:\windows\system32\dllcache\vbscript.dll
2010-02-24 10:16 181,632 ——– c:\windows\system32\MpSigStub.exe
2010-02-24 08:11 455,680 ——– c:\windows\system32\dllcache\mrxsmb.sys
2010-02-23 00:20 634,648 ——– c:\windows\system32\dllcache\iexplore.exe
2010-02-23 00:18 161,792 ——– c:\windows\system32\dllcache\ieakui.dll
2010-02-17 09:10 2,189,952 a——- c:\windows\system32\ntoskrnl.exe
2010-02-17 09:10 2,189,952 ——– c:\windows\system32\dllcache\ntoskrnl.exe
2010-02-16 09:08 2,146,304 ——– c:\windows\system32\dllcache\ntkrnlmp.exe
2010-02-16 08:25 2,066,816 a——- c:\windows\system32\ntkrnlpa.exe
2010-02-16 08:25 2,066,816 ——– c:\windows\system32\dllcache\ntkrnlpa.exe
2010-02-16 08:25 2,024,448 ——– c:\windows\system32\dllcache\ntkrpamp.exe
2010-02-11 23:33 100,864 a——- c:\windows\system32\6to4svc.dll
2010-02-11 23:33 100,864 ——– c:\windows\system32\dllcache\6to4svc.dll
2010-02-11 07:02 226,880 ——– c:\windows\system32\dllcache\tcpip6.sys
2009-02-08 17:44 87,608 a——- c:\docume~1\admin\applic~1\inst.exe
2009-02-08 17:44 47,360 a——- c:\docume~1\admin\applic~1\pcouffin.sys
2009-01-11 12:30 603 a——- c:\program files\Shortcut to WS_FTP95.lnk
2008-05-19 16:02 955,704 a——- c:\program files\TreeSizeFree.exe
2006-09-13 07:21 2,567,672 a——- c:\program files\Wimpy FLV Player.exe
2009-01-05 21:15 8 —shr– c:\windows\system32\1C02B127CC.sys
2008-11-23 18:27 88 —shr– c:\windows\system32\AB72D94BAB.sys
2009-01-05 21:15 5,226 a–sh— c:\windows\system32\KGyGaAvL.sys
2008-09-23 03:06 32,768 a–sh— c:\windows\system32\config\systemprofile\local settings\history\history.ie5\mshist012008092320080924\index.dat

============= FINISH: 12:35:01.62 ===============
Gomer.txt:
GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-05-01 12:45:12
Windows 5.1.2600 Service Pack 3
Running: qhiwyj20.exe; Driver: C:\DOCUME~1\admin\LOCALS~1\Temp\fwtdqpob.sys


—- Kernel code sections - GMER 1.0.15 —-

init C:\WINDOWS\system32\drivers\senfilt.sys entry point in "init" section [0xF8328F80]
? C:\DOCUME~1\admin\LOCALS~1\Temp\fwtdqpog.sys The system cannot find the file specified. !

—- User code sections - GMER 1.0.15 —-

.text C:\Program Files\Internet Explorer\iexplore.exe[316] USER32.dll!DialogBoxParamW 7E4247AB 5 Bytes JMP 3E1DF4B9 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[316] USER32.dll!DialogBoxIndirectParamW 7E432072 5 Bytes JMP 3E352046 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[316] USER32.dll!MessageBoxIndirectA 7E43A082 5 Bytes JMP 3E351FC7 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[316] USER32.dll!DialogBoxParamA 7E43B144 5 Bytes JMP 3E35200B C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[316] USER32.dll!MessageBoxExW 7E450838 5 Bytes JMP 3E351F53 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[316] USER32.dll!MessageBoxExA 7E45085C 5 Bytes JMP 3E351F8D C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[316] USER32.dll!DialogBoxIndirectParamA 7E456D7D 1 Byte [E9]
.text C:\Program Files\Internet Explorer\iexplore.exe[316] USER32.dll!DialogBoxIndirectParamA 7E456D7D 5 Bytes JMP 3E352081 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[316] USER32.dll!MessageBoxIndirectW 7E4664D5 5 Bytes JMP 3E2017EA C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[316] ole32.dll!OleLoadFromStream 77529C85 5 Bytes JMP 3E352243 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)

—- Devices - GMER 1.0.15 —-

Device Ntfs.sys (NT File System Driver/Microsoft Corporation)
Device Fastfat.SYS (Fast FAT File System Driver/Microsoft Corporation)
Device mrxsmb.sys (Windows NT SMB Minirdr/Microsoft Corporation)

AttachedDevice fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)

Device \FileSystem\Cdfs \Cdfs DLAIFS_M.SYS (Drive Letter Access Component/Sonic Solutions)

—- EOF - GMER 1.0.15 —-


Thanks
Spidey
Hello,
Welcome to WhatTheTech. My name is mowman, and I will be helping you fix your problems.

If you do not make a reply in 5 days, we will have to close your topic.

You may want to keep the link to this topic in your favorites. Alternatively, you can click the Options button at the top bar of this topic and Track this topic. The topics you are tracking can be found by clicking on My Topics at the top of any page.

Please take note of some guidelines for this fix:

•Refrain from making any changes to your computer including installing/uninstall programs, deleting files, modifying the registry, and running scanners or tools. Doing so could cause changes to the directions I have to give you and prolong the time required. Further more, you should not be taking any advice relating to this computer from any other source throughout the course of this fix.
•If you do not understand any step(s) provided, please do not hesitate to ask before continuing. I would much rather clarify instructions or explain them differently than have something important broken.
•Even if things appear to be better, it might not mean we are finished. Please continue to follow my instructions and reply back until I give you the "all clean". We do not want to clean you part-way, only to have the system re-infect itself.
•Please reply using the button in the lower right hand corner of your screen. Do not start a new topic. The logs that you post should be pasted directly into the reply.
Only attach them if requested or if they do not fit into the post
•Please be aware that I am still in training, and all of my replies to you will be checked for accuracy by one of our experts to ensure that I am giving you the best possible advice.
•This may cause a delay in response time, but I will do my best to keep it as short as possible.
•I will reply back shortly with instructions.
Hi Mowman…… I'll follow the instructions as you send them. I appreciate the help and all the time you give. Thanks, Sidey
Hello spidey.

Peer-to-Peer Programs Warning
Your log shows that you are using so called peer-to-peer or file-sharing programs. These programs allow to share files between users as the name(s) suggest. In today's world cyber crime has come to an enormous dimension and any means is used to infect personal computers to make use of their stored data or machine power for further propagation of the malware files. A popular means is the use of file-sharing tools as a tremendous amount of prospective victims can be reached through it.

It is therefore possible to be infected by downloading manipulated files via peer-to-peer tools and thus suggested to be used with intense care.

It is also important to note that sharing entertainment files and proprietary software infringes the copyright laws in many countries over the world and you are putting yourself at risk of being indicted through organizations watching over the rights of the authors of such files (i.e. the RIAA for music files, or the MPAA for movie files in the USA) or the authors of the files themselves.

It is your decision whether or not you wish to keep your program(s). However, please refrain from using them until your computer has been declared clean


Please do the following.

Download ComboFix from one of these locations:

Link 1
Link 2


* IMPORTANT !!! Save ComboFix.exe to your Desktop


  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools
  • See this Link for programs that need to be disabled and instruction on how to disable them.
  • Remember to re-enable them when we're done.

  • Double click on ComboFix.exe & follow the prompts.

  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


[external image: Posted Image]



Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.

*If there is no internet connection when Combofix has completely finished then restart your computer to restore back the connections.
Hi Mowman,
I've run the combo fix and here's the log:
ComboFix 10-05-03.03 - admin 05/03/2010 21:48:55.1.1 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.510.262 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: Microsoft Security Essentials *On-access scanning disabled* (Updated) {BCF43643-A118-4432-AEDE-D861FCBCFCDF}
AV: Symantec AntiVirus Corporate Edition *On-access scanning disabled* (Outdated) {FB06448E-52B8-493A-90F3-E43226D3305C}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\admin\Application Data\inst.exe
c:\program files\WindowsUpdate
c:\windows\system32\gotomon.log

.
((((((((((((((((((((((((( Files Created from 2010-04-04 to 2010-05-04 )))))))))))))))))))))))))))))))
.

2010-05-01 17:25 . 2010-05-01 17:25 ——– d—–w- c:\program files\ERUNT
2010-04-30 23:04 . 2010-04-30 23:04 96512 —-a-w- c:\windows\system32\drivers\hsiwouul.sys
2010-04-30 02:44 . 2010-04-30 02:44 96512 —-a-w- c:\windows\system32\drivers\ATAPI.SYS
2010-04-27 22:45 . 2010-04-27 22:45 664 —-a-w- c:\windows\system32\d3d9caps.dat
2010-04-27 22:45 . 2010-04-27 22:45 552 —-a-w- c:\windows\system32\d3d8caps.dat
2010-04-27 22:44 . 2010-04-27 22:44 ——– d—–w- c:\documents and settings\NetworkService\Local Settings\Application Data\Adobe
2010-04-25 19:35 . 2010-04-25 19:35 ——– d—–w- c:\windows\system32\wbem\Repository

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-05-04 01:55 . 2009-01-02 03:15 ——– d—–w- c:\documents and settings\admin\Application Data\MailWasherFree
2010-04-30 23:17 . 2010-02-21 18:45 ——– d—–w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2010-04-29 01:48 . 2009-01-01 20:06 ——– d—–w- c:\documents and settings\admin\Application Data\U3
2010-04-27 12:53 . 2010-03-04 00:19 ——– d—–w- c:\documents and settings\All Users\Application Data\Microsoft Help
2010-04-23 00:39 . 2009-02-08 22:44 ——– d—–w- c:\documents and settings\admin\Application Data\Vso
2010-04-07 22:50 . 2009-01-11 22:45 ——– d—–w- c:\documents and settings\admin\Application Data\Canon
2010-03-30 01:08 . 2009-05-05 02:46 ——– d—–w- c:\program files\ICQ6.5
2010-03-12 00:53 . 2010-03-12 00:52 ——– d—–w- c:\program files\Microsoft Security Essentials
2010-03-11 12:38 . 2004-08-11 22:00 832512 —-a-w- c:\windows\system32\wininet.dll
2010-03-11 12:38 . 2004-08-11 22:00 78336 —-a-w- c:\windows\system32\ieencode.dll
2010-03-11 12:38 . 2004-08-11 22:00 17408 ——w- c:\windows\system32\corpol.dll
2010-03-09 11:09 . 2004-08-11 22:00 430080 —-a-w- c:\windows\system32\vbscript.dll
2010-03-07 21:24 . 2008-07-15 18:32 568944 —-a-w- c:\documents and settings\admin\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-02-24 15:16 . 2010-03-12 00:55 181632 ——w- c:\windows\system32\MpSigStub.exe
2010-02-24 13:11 . 2006-09-19 14:40 455680 —-a-w- c:\windows\system32\drivers\mrxsmb.sys
2010-02-22 03:59 . 2010-02-22 03:59 10134 —-a-r- c:\documents and settings\admin\Application Data\Microsoft\Installer\{CAE7D1D9-3794-4169-B4DD-964ADBC534EE}\ARPPRODUCTICON.exe
2010-02-17 14:10 . 2004-08-11 22:00 2189952 —-a-w- c:\windows\system32\ntoskrnl.exe
2010-02-16 13:25 . 2004-08-04 03:59 2066816 —-a-w- c:\windows\system32\ntkrnlpa.exe
2010-02-12 04:33 . 2004-08-11 22:00 100864 —-a-w- c:\windows\system32\6to4svc.dll
2010-02-11 12:02 . 2004-08-11 22:00 226880 —-a-w- c:\windows\system32\drivers\tcpip6.sys
2009-01-11 17:30 . 2009-01-11 17:30 603 —-a-w- c:\program files\Shortcut to WS_FTP95.lnk
2008-05-19 21:02 . 2008-05-19 21:02 955704 —-a-w- c:\program files\TreeSizeFree.exe
2006-09-13 12:21 . 2009-01-03 20:51 2567672 —-a-w- c:\program files\Wimpy FLV Player.exe
2009-02-28 00:17 . 2009-02-28 00:17 24 –sh–w- c:\windows\S6AA62EC7.tmp
2009-01-06 02:15 . 2009-01-06 02:15 8 –sh–r- c:\windows\system32\1C02B127CC.sys
2008-11-23 23:27 . 2006-11-15 16:05 88 –sh–r- c:\windows\system32\AB72D94BAB.sys
2009-01-06 02:15 . 2006-11-15 16:05 5226 –sha-w- c:\windows\system32\KGyGaAvL.sys
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DLA"="c:\windows\System32\DLA\DLACTRLW.EXE" [2005-09-08 122940]
"MSSE"="c:\program files\Microsoft Security Essentials\msseces.exe" [2010-02-21 1093208]
"Malwarebytes Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2009-09-10 1312080]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2010-03-24 18:17 952768 —-a-w- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\cdloader]
2008-07-22 16:45 50520 —-a-w- c:\documents and settings\admin\Application Data\mjusbsp\cdloader2.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
2008-04-14 00:12 15360 —-a-w- c:\windows\system32\ctfmon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DMXLauncher]
2005-10-05 08:12 94208 —-a-w- c:\program files\Dell\Media Experience\DMXLauncher.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HotKeysCmds]
2005-04-06 00:19 77824 —-a-w- c:\windows\system32\hkcmd.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IgfxTray]
2005-04-06 00:22 94208 —-a-w- c:\windows\system32\igfxtray.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSScheduler]
2005-06-10 15:44 81920 —-a-w- c:\program files\Common Files\InstallShield\UpdateService\issch.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MaxMenuMgr]
2009-01-16 21:31 181544 —-a-w- c:\program files\Seagate\SeagateManager\FreeAgent Status\stxmenumgr.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSKDetectorExe]
2005-07-13 00:05 1117184 —-a-w- c:\program files\McAfee\SpamKiller\MSKDetct.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Omnipage]
2002-06-03 17:38 49152 —-a-w- c:\program files\ScanSoft\OmniPageSE\opware32.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Persistence]
2005-04-06 00:23 114688 —-a-w- c:\windows\system32\igfxpers.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2006-09-19 15:08 98304 —-a-w- c:\program files\QuickTime\qttask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RealTray]
2006-09-19 15:08 26112 —-a-w- c:\program files\Real\RealPlayer\realplay.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMAXPnP]
2004-10-15 00:42 1404928 —-a-w- c:\program files\Analog Devices\Core\smax4pnp.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"TrkWks"=2 (0x2)
"Themes"=2 (0x2)
"LexBceS"=2 (0x2)
"JavaQuickStarterService"=2 (0x2)
"IntuitUpdateService"=2 (0x2)
"FreeAgentGoNext Service"=2 (0x2)

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"DisableNotifications"= 1 (0x1)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Dell\\Dell Laser MFP 1815\\NetworkScan\\DNSCST.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Documents and Settings\\admin\\Application Data\\mjusbsp\\magicJack.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"f:\\Program Files\\WS_FTP\\WS_FTP95.exe"=
"f:\\Program Files\\LimeWire\\LimeWire.exe"=
"c:\\Program Files\\ICQ6.5\\ICQ.exe"=
"c:\\Program Files\\ScanSoft\\OmniPageSE\\EregEng\\NAVBrowser.exe"=
"c:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=

R2 LogWatch;Event Log Watch;c:\program files\CA\SharedComponents\CA_LIC\LogWatNT.exe [9/20/2002 11:29 AM 53248]
S1 MpKsl0f135ce1;MpKsl0f135ce1;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{4669EF94-AB70-4E78-B64A-8E1F26187FE3}\MpKsl0f135ce1.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{4669EF94-AB70-4E78-B64A-8E1F26187FE3}\MpKsl0f135ce1.sys [?]
S1 MpKsl4894e515;MpKsl4894e515;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{4669EF94-AB70-4E78-B64A-8E1F26187FE3}\MpKsl4894e515.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{4669EF94-AB70-4E78-B64A-8E1F26187FE3}\MpKsl4894e515.sys [?]
S3 CA_LIC_CLNT;CA License Client;c:\program files\CA\SharedComponents\CA_LIC\lic98rmt.exe [9/20/2002 11:27 AM 77824]
S3 CA_LIC_SRVR;CA License Server;c:\program files\CA\SharedComponents\CA_LIC\lic98rmtd.exe [9/20/2002 11:41 AM 77824]
S4 FreeAgentGoNext Service;Seagate Service;c:\program files\Seagate\SeagateManager\Sync\FreeAgentService.exe [1/16/2009 4:31 PM 161064]
.
Contents of the 'Scheduled Tasks' folder

2010-05-03 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Microsoft Security Essentials\MpCmdRun.exe [2009-12-10 00:02]

2010-05-01 c:\windows\Tasks\OGALogon.job
- c:\windows\system32\OGAEXEC.exe [2009-08-03 21:07]
.
.
——- Supplementary Scan ——-
.
uStart Page = about:blank
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr9/*http://www.yahoo.com/ext/search/search.html
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ie/defaults/su/msgr9/*http://www.yahoo.com
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
DPF: {C111A91F-D4EC-4D22-8D27-C3BCB0389F43} - hxxp://www.boydsnest-ti.com/activex/AMC.cab
DPF: {DE625294-70E6-45ED-B895-CFFA13AEB044} - hxxp://205.241.135.70/activex/AMC.cab
FF - ProfilePath - c:\documents and settings\admin\Application Data\Mozilla\Firefox\Profiles\arkm7om1.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/
FF - plugin: c:\program files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
.
- - - - ORPHANS REMOVED - - - -

MSConfigStartUp-fasumyjg - c:\documents and settings\admin\Local Settings\Application Data\vshsdm\noxisysguard.exe
MSConfigStartUp-SpyHunter Security Suite - c:\program files\Enigma Software Group\SpyHunter\SpyHunter3.exe
MSConfigStartUp-swg - c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-05-03 21:54
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2010-05-03 21:56:37
ComboFix-quarantined-files.txt 2010-05-04 02:56

Pre-Run: 97,503,993,856 bytes free
Post-Run: 97,753,100,288 bytes free

WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Professional" /fastdetect /NoExecute=OptOut

- - End Of File - - 8AEA02B28657DAE667A559BC46F364AA


Thanks again,
Spidey
Hello spidey,please do the following.


Please scan the following files


  • Please visit Virus Total by clicking here.
  • Click the Browse button and search for the following file: c:\windows\system32\drivers\hsiwouul.sys
  • Click Open.
  • Then click Send File.
  • Please be patient while the file is scanned.
  • If Virus Total tells you that the file has already been scanned, click "reanalyse now".

  • Once the scan results appear, copy and paste them into Notepad and repeat the procedure for the following file(s):

  • c:\windows\system32\1C02B127CC.sys
  • c:\windows\system32\AB72D94BAB.sys
  • Please provide the results from the scans in your next reply.


You already have Malwarebytes installed.Please update and run a quick scan.

In your next reply please post the results from Virustotal and the MBAM log
Hi Mowman,
The last two files that you wanted me to put through virus total was not on the computer, I did a file search and came up with nothing. Here's the rest that you want:
c:\windows\system32\drivers\hsiwouul.sys

File atapi.sys received on 2010.05.04 22:36:58 (UTC)
Current status: finished

Result: 1/41 (2.44%)
Compact Print results
Antivirus Version Last Update Result
a-squared 4.5.0.50 2010.05.04 -
AhnLab-V3 2010.05.04.00 2010.05.04 -
AntiVir 8.2.1.224 2010.05.04 -
Antiy-AVL 2.0.3.7 2010.04.30 -
Authentium 5.2.0.5 2010.05.05 -
Avast 4.8.1351.0 2010.05.04 -
Avast5 5.0.332.0 2010.05.04 -
AVG 9.0.0.787 2010.05.04 -
BitDefender 7.2 2010.05.05 -
CAT-QuickHeal 10.00 2010.05.04 -
ClamAV 0.96.0.3-git 2010.05.04 -
Comodo 4766 2010.05.05 -
DrWeb 5.0.2.03300 2010.05.04 -
eSafe 7.0.17.0 2010.05.03 Win32.Rootkit
eTrust-Vet 35.2.7468 2010.05.04 -
F-Prot 4.5.1.85 2010.05.05 -
F-Secure 9.0.15370.0 2010.05.04 -
Fortinet 4.0.14.0 2010.05.03 -
GData 21 2010.05.04 -
Ikarus T3.1.1.84.0 2010.05.04 -
Jiangmin 13.0.900 2010.05.04 -
Kaspersky 7.0.0.125 2010.05.04 -
McAfee 5.400.0.1158 2010.05.05 -
McAfee-GW-Edition 2010.1 2010.05.04 -
Microsoft 1.5703 2010.05.04 -
NOD32 5086 2010.05.04 -
Norman 6.04.12 2010.05.04 -
nProtect 2010-05-04.01 2010.05.04 -
Panda 10.0.2.7 2010.05.04 -
PCTools 7.0.3.5 2010.05.04 -
Prevx 3.0 2010.05.05 -
Rising 22.46.01.01 2010.05.04 -
Sophos 4.53.0 2010.05.04 -
Sunbelt 6261 2010.05.04 -
Symantec 20091.2.0.41 2010.05.05 -
TheHacker 6.5.2.0.275 2010.05.03 -
TrendMicro 9.120.0.1004 2010.05.04 -
TrendMicro-HouseCall 9.120.0.1004 2010.05.05 -
VBA32 3.12.12.4 2010.05.04 -
ViRobot 2010.5.4.2303 2010.05.04 -
VirusBuster 5.0.27.0 2010.05.04 -
Additional information
File size: 96512 bytes
MD5 : 9f3a2f5aa6875c72bf062c712cfa2674
SHA1 : a719156e8ad67456556a02c34e762944234e7a44
SHA256: b4df1d2c56a593c6b54de57395e3b51d288f547842893b32b0f59228a0cf70b9
PEInfo: PE Structure information

( base data )
entrypointaddress.: 0x159F7
timedatestamp…..: 0x4802539D (Sun Apr 13 20:40:29 2008)
machinetype…….: 0x14C (Intel I386)

( 9 sections )
name viradd virsiz rawdsiz ntrpy md5
.text 0x380 0x97BA 0x9800 6.45 0d7d81391f33c6450a81be1e3ac8c7b7
NONPAGE 0x9B80 0x18E8 0x1900 6.48 c74a833abd81cc5d037de168e055ad29
.rdata 0xB480 0xA64 0xA80 4.31 8523651899e28819a14bf9415af25708
.data 0xBF00 0xD94 0xE00 0.45 3575b51634ae7a56f55f1ee0a6213834
PAGESCAN 0xCD00 0x157F 0x1580 6.20 dc4c309c4db9576daa752fdd125fccf9
PAGE 0xE280 0x61DA 0x6200 6.46 40b83d4d552384e58a03517a98eb4863
INIT 0x14480 0x22BE 0x2300 6.47 906462abc478368424ea462d5868d2e3
.rsrc 0x16780 0x3E0 0x400 3.36 8fd2d82e745b289c28bc056d3a0d62ab
.reloc 0x16B80 0xD20 0xD80 6.39 ce2b0898cc0e40b618e5df9099f6be45

( 0 imports )


( 0 exports )

TrID : File type identification
Win32 Executable Generic (68.0%)
Generic Win/DOS Executable (15.9%)
DOS Executable Generic (15.9%)
Autodesk FLIC Image File (extensions: flc, fli, cel) (0.0%)
ThreatExpert: http://www.threatexpert.com/report.aspx?md…f062c712cfa2674
ssdeep: 1536:MwXpkfV74F1D7yNEZIHRRJMohmus27G1j/XBoDQi7oaRMJfYHFktprll1KbDD0uu:MQ+N74vkEZIxMohjsimBoDTRMBwFktZu
sigcheck: publisher….: Microsoft Corporation
copyright….: © Microsoft Corporation. All rights reserved.
product……: Microsoft_ Windows_ Operating System
description..: IDE/ATAPI Port Driver
original name: atapi.sys
internal name: atapi.sys
file version.: 5.1.2600.5512 (xpsp.080413-2108)
comments…..: n/a
signers……: -
signing date.: -
verified…..: Unsigned

PEiD : -
packers (Kaspersky): PE_Patch
RDS : NSRL Reference Data Set
-


c:\windows\system32\1C02B127CC.sys

Not found on computer

c:\windows\system32\AB72D94BAB.sys

Not found on computer

Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org

Database version: 4052

Windows 5.1.2600 Service Pack 3
Internet Explorer 7.0.5730.13

5/4/2010 9:21:12 PM
mbam-log-2010-05-04 (21-21-12).txt

Scan type: Quick scan
Objects scanned: 142833
Time elapsed: 10 minute(s), 28 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 1
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\FIREFOX.EXE\shell\safemode\command\(default) (Hijack.StartMenuInternet) -> Bad: ("C:\Documents and Settings\admin\Local Settings\Application Data\ave.exe" /START "C:\Program Files\Mozilla Firefox\firefox.exe" -safe-mode) Good: (firefox.exe -safe-mode) -> Quarantined and deleted successfully.

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)
Hello spidey,please do the following.

Your Malwarebytes log showed you are using an old database,please update and run another quick scan.Post the log.


I need you to run the following scan: Eset Online Scanner
  • Place a check mark in the box YES, I accept the Terms Of Use
  • Click the Start button.
  • Now click the Install button.
  • Click Start. The scanner engine will initialize and update.
  • Do Not place a check mark in the box beside Remove found threats.
  • Click the Scan button. The scan will now run, please be patient.
  • When the scan finishes click the Details tab.
  • Copy and paste the contents of the C:\ProgramFiles\EsetOnlineScanner\log.txt into your next reply.
Hi Mowmwn, I updated Malwarebytes again today and ran it, here's the results: Malwarebytes' Anti-Malware 1.46 www.malwarebytes.org Database version: 4070 Windows 5.1.2600 Service Pack 3 Internet Explorer 7.0.5730.13 5/5/2010 6:08:38 PM mbam-log-2010-05-05 (18-08-38).txt Scan type: Quick scan Objects scanned: 144017 Time elapsed: 15 minute(s), 11 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected) Eset results: :\My Documents\My Received Files\reflexive.exe probably a variant of Win32/Agent trojan Thanks, Spidey
Hi spidey,please run GMER.

  • .
  • Double click GMER.exe. If asked to allow gmer.sys driver to load, please consent .
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.

    [external image: Posted Image]
    Click the image to enlarge it
  • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and attach it in your reply.

**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries

.
Hi Mowman,
Here's the gmer.txt

GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-05-06 18:43:14
Windows 5.1.2600 Service Pack 3
Running: qhiwyj20.exe; Driver: C:\DOCUME~1\admin\LOCALS~1\Temp\fwtdqpob.sys


—- Kernel code sections - GMER 1.0.15 —-

init C:\WINDOWS\system32\drivers\senfilt.sys entry point in "init" section [0xF7A89F80]

—- User code sections - GMER 1.0.15 —-

.text C:\Program Files\internet explorer\iexplore.exe[3836] USER32.dll!DialogBoxParamW 7E4247AB 5 Bytes JMP 3E1DF4B9 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\internet explorer\iexplore.exe[3836] USER32.dll!DialogBoxIndirectParamW 7E432072 5 Bytes JMP 3E352046 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\internet explorer\iexplore.exe[3836] USER32.dll!MessageBoxIndirectA 7E43A082 5 Bytes JMP 3E351FC7 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\internet explorer\iexplore.exe[3836] USER32.dll!DialogBoxParamA 7E43B144 5 Bytes JMP 3E35200B C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\internet explorer\iexplore.exe[3836] USER32.dll!MessageBoxExW 7E450838 5 Bytes JMP 3E351F53 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\internet explorer\iexplore.exe[3836] USER32.dll!MessageBoxExA 7E45085C 5 Bytes JMP 3E351F8D C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\internet explorer\iexplore.exe[3836] USER32.dll!DialogBoxIndirectParamA 7E456D7D 1 Byte [E9]
.text C:\Program Files\internet explorer\iexplore.exe[3836] USER32.dll!DialogBoxIndirectParamA 7E456D7D 5 Bytes JMP 3E352081 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\internet explorer\iexplore.exe[3836] USER32.dll!MessageBoxIndirectW 7E4664D5 5 Bytes JMP 3E2017EA C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\internet explorer\iexplore.exe[3836] ole32.dll!OleLoadFromStream 77529C85 5 Bytes JMP 3E352243 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)

—- Disk sectors - GMER 1.0.15 —-

Disk \Device\Harddisk0\DR0 sector 01: copy of MBR
Disk \Device\Harddisk0\DR0 sector 02: copy of MBR
Disk \Device\Harddisk0\DR0 sector 03: copy of MBR
Disk \Device\Harddisk0\DR0 sector 04: copy of MBR
Disk \Device\Harddisk0\DR0 sector 05: copy of MBR
Disk \Device\Harddisk0\DR0 sector 06: copy of MBR
Disk \Device\Harddisk0\DR0 sector 07: copy of MBR
Disk \Device\Harddisk0\DR0 sector 08: copy of MBR
Disk \Device\Harddisk0\DR0 sector 09: copy of MBR
Disk \Device\Harddisk0\DR0 sector 10: rootkit-like behavior; copy of MBR
Disk \Device\Harddisk0\DR0 sector 11: rootkit-like behavior; copy of MBR
Disk \Device\Harddisk0\DR0 sector 12: copy of MBR
Disk \Device\Harddisk0\DR0 sector 13: copy of MBR
Disk \Device\Harddisk0\DR0 sector 14: copy of MBR
Disk \Device\Harddisk0\DR0 sector 15: copy of MBR
Disk \Device\Harddisk0\DR0 sector 16: copy of MBR
Disk \Device\Harddisk0\DR0 sector 17: copy of MBR
Disk \Device\Harddisk0\DR0 sector 18: copy of MBR
Disk \Device\Harddisk0\DR0 sector 19: copy of MBR
Disk \Device\Harddisk0\DR0 sector 20: copy of MBR
Disk \Device\Harddisk0\DR0 sector 21: copy of MBR
Disk \Device\Harddisk0\DR0 sector 22: copy of MBR
Disk \Device\Harddisk0\DR0 sector 23: copy of MBR
Disk \Device\Harddisk0\DR0 sector 24: copy of MBR
Disk \Device\Harddisk0\DR0 sector 25: copy of MBR
Disk \Device\Harddisk0\DR0 sector 26: copy of MBR
Disk \Device\Harddisk0\DR0 sector 27: copy of MBR
Disk \Device\Harddisk0\DR0 sector 28: copy of MBR
Disk \Device\Harddisk0\DR0 sector 29: copy of MBR
Disk \Device\Harddisk0\DR0 sector 30: copy of MBR
Disk \Device\Harddisk0\DR0 sector 31: copy of MBR
Disk \Device\Harddisk0\DR0 sector 32: copy of MBR
Disk \Device\Harddisk0\DR0 sector 33: copy of MBR
Disk \Device\Harddisk0\DR0 sector 34: copy of MBR
Disk \Device\Harddisk0\DR0 sector 35: copy of MBR
Disk \Device\Harddisk0\DR0 sector 36: copy of MBR
Disk \Device\Harddisk0\DR0 sector 37: copy of MBR
Disk \Device\Harddisk0\DR0 sector 38: copy of MBR
Disk \Device\Harddisk0\DR0 sector 39: copy of MBR
Disk \Device\Harddisk0\DR0 sector 40: copy of MBR
Disk \Device\Harddisk0\DR0 sector 41: copy of MBR
Disk \Device\Harddisk0\DR0 sector 42: copy of MBR
Disk \Device\Harddisk0\DR0 sector 43: copy of MBR
Disk \Device\Harddisk0\DR0 sector 44: copy of MBR
Disk \Device\Harddisk0\DR0 sector 45: copy of MBR
Disk \Device\Harddisk0\DR0 sector 46: copy of MBR
Disk \Device\Harddisk0\DR0 sector 47: copy of MBR
Disk \Device\Harddisk0\DR0 sector 48: copy of MBR
Disk \Device\Harddisk0\DR0 sector 49: copy of MBR
Disk \Device\Harddisk0\DR0 sector 50: copy of MBR
Disk \Device\Harddisk0\DR0 sector 51: copy of MBR
Disk \Device\Harddisk0\DR0 sector 52: copy of MBR
Disk \Device\Harddisk0\DR0 sector 53: copy of MBR
Disk \Device\Harddisk0\DR0 sector 54: copy of MBR
Disk \Device\Harddisk0\DR0 sector 55: copy of MBR
Disk \Device\Harddisk0\DR0 sector 56: copy of MBR
Disk \Device\Harddisk0\DR0 sector 57: rootkit-like behavior; copy of MBR
Disk \Device\Harddisk0\DR0 sector 58: copy of MBR
Disk \Device\Harddisk0\DR0 sector 59: copy of MBR
Disk \Device\Harddisk0\DR0 sector 60: copy of MBR
Disk \Device\Harddisk0\DR0 sector 61: copy of MBR
Disk \Device\Harddisk0\DR0 sector 62: copy of MBR
Disk \Device\Harddisk0\DR0 sector 63: rootkit-like behavior; copy of MBR

—- EOF - GMER 1.0.15 —-


Thanks,
Spidey
Hello spidey,please do the following.

  • Download TDSSKiller and save it to your Desktop.
  • Extract its contents to your desktop and make sure TDSSKiller.exe (the contents of the zipped file) is on the Desktop itself, not within a folder on the desktop.

  • Click on the exe file to run it.
  • Once completed it will create a log in your C:\ drive called TDSSKiller_*** (*** denotes version & date)
  • please post the content of the TDSSKiller log

Also tell me how the computer is running now.Thanks.
Hi Mowman, Here's the results of the TDSSKiller: 18:23:53:359 3036 TDSS rootkit removing tool [removed] Mar 22 2010 10:43:04 18:23:53:359 3036 ================================================================================ 18:23:53:359 3036 SystemInfo: 18:23:53:359 3036 OS Version: 5.1.2600 ServicePack: 3.0 18:23:53:359 3036 Product type: Workstation 18:23:53:359 3036 ComputerName: GEORGE 18:23:53:359 3036 UserName: admin 18:23:53:359 3036 Windows directory: C:\WINDOWS 18:23:53:359 3036 Processor architecture: Intel x86 18:23:53:359 3036 Number of processors: 1 18:23:53:359 3036 Page size: 0x1000 18:23:53:359 3036 Boot type: Normal boot 18:23:53:359 3036 ================================================================================ 18:23:53:500 3036 UnloadDriverW: NtUnloadDriver error 2 18:23:53:500 3036 ForceUnloadDriverW: UnloadDriverW(klmd21) error 2 18:23:53:703 3036 wfopen_ex: Trying to open file C:\WINDOWS\system32\config\system 18:23:53:703 3036 wfopen_ex: MyNtCreateFileW error 32 (C0000043) 18:23:53:703 3036 wfopen_ex: Trying to KLMD file open 18:23:53:703 3036 wfopen_ex: File opened ok (Flags 2) 18:23:53:703 3036 wfopen_ex: Trying to open file C:\WINDOWS\system32\config\software 18:23:53:703 3036 wfopen_ex: MyNtCreateFileW error 32 (C0000043) 18:23:53:703 3036 wfopen_ex: Trying to KLMD file open 18:23:53:703 3036 wfopen_ex: File opened ok (Flags 2) 18:23:53:703 3036 Initialize success 18:23:53:703 3036 18:23:53:703 3036 Scanning Services … 18:23:54:062 3036 Raw services enum returned 357 services 18:23:54:062 3036 18:23:54:062 3036 Scanning Kernel memory … 18:23:54:062 3036 Devices to scan: 7 18:23:54:062 3036 18:23:54:062 3036 Driver Name: Disk 18:23:54:062 3036 IRP_MJ_CREATE : F857DBB0 18:23:54:062 3036 IRP_MJ_CREATE_NAMED_PIPE : 804FA88E 18:23:54:062 3036 IRP_MJ_CLOSE : F857DBB0 18:23:54:062 3036 IRP_MJ_READ : F8577D1F 18:23:54:062 3036 IRP_MJ_WRITE : F8577D1F 18:23:54:062 3036 IRP_MJ_QUERY_INFORMATION : 804FA88E 18:23:54:062 3036 IRP_MJ_SET_INFORMATION : 804FA88E 18:23:54:062 3036 IRP_MJ_QUERY_EA : 804FA88E 18:23:54:062 3036 IRP_MJ_SET_EA : 804FA88E 18:23:54:062 3036 IRP_MJ_FLUSH_BUFFERS : F85782E2 18:23:54:062 3036 IRP_MJ_QUERY_VOLUME_INFORMATION : 804FA88E 18:23:54:062 3036 IRP_MJ_SET_VOLUME_INFORMATION : 804FA88E 18:23:54:062 3036 IRP_MJ_DIRECTORY_CONTROL : 804FA88E 18:23:54:062 3036 IRP_MJ_FILE_SYSTEM_CONTROL : 804FA88E 18:23:54:062 3036 IRP_MJ_DEVICE_CONTROL : F85783BB 18:23:54:062 3036 IRP_MJ_INTERNAL_DEVICE_CONTROL : F857BF28 18:23:54:062 3036 IRP_MJ_SHUTDOWN : F85782E2 18:23:54:062 3036 IRP_MJ_LOCK_CONTROL : 804FA88E 18:23:54:062 3036 IRP_MJ_CLEANUP : 804FA88E 18:23:54:062 3036 IRP_MJ_CREATE_MAILSLOT : 804FA88E 18:23:54:062 3036 IRP_MJ_QUERY_SECURITY : 804FA88E 18:23:54:062 3036 IRP_MJ_SET_SECURITY : 804FA88E 18:23:54:062 3036 IRP_MJ_POWER : F8579C82 18:23:54:062 3036 IRP_MJ_SYSTEM_CONTROL : F857E99E 18:23:54:062 3036 IRP_MJ_DEVICE_CHANGE : 804FA88E 18:23:54:062 3036 IRP_MJ_QUERY_QUOTA : 804FA88E 18:23:54:062 3036 IRP_MJ_SET_QUOTA : 804FA88E 18:23:54:203 3036 C:\WINDOWS\system32\DRIVERS\disk.sys - Verdict: 1 18:23:54:203 3036 18:23:54:203 3036 Driver Name: Disk 18:23:54:203 3036 IRP_MJ_CREATE : F857DBB0 18:23:54:203 3036 IRP_MJ_CREATE_NAMED_PIPE : 804FA88E 18:23:54:203 3036 IRP_MJ_CLOSE : F857DBB0 18:23:54:203 3036 IRP_MJ_READ : F8577D1F 18:23:54:203 3036 IRP_MJ_WRITE : F8577D1F 18:23:54:203 3036 IRP_MJ_QUERY_INFORMATION : 804FA88E 18:23:54:203 3036 IRP_MJ_SET_INFORMATION : 804FA88E 18:23:54:203 3036 IRP_MJ_QUERY_EA : 804FA88E 18:23:54:203 3036 IRP_MJ_SET_EA : 804FA88E 18:23:54:203 3036 IRP_MJ_FLUSH_BUFFERS : F85782E2 18:23:54:203 3036 IRP_MJ_QUERY_VOLUME_INFORMATION : 804FA88E 18:23:54:203 3036 IRP_MJ_SET_VOLUME_INFORMATION : 804FA88E 18:23:54:203 3036 IRP_MJ_DIRECTORY_CONTROL : 804FA88E 18:23:54:203 3036 IRP_MJ_FILE_SYSTEM_CONTROL : 804FA88E 18:23:54:203 3036 IRP_MJ_DEVICE_CONTROL : F85783BB 18:23:54:203 3036 IRP_MJ_INTERNAL_DEVICE_CONTROL : F857BF28 18:23:54:203 3036 IRP_MJ_SHUTDOWN : F85782E2 18:23:54:203 3036 IRP_MJ_LOCK_CONTROL : 804FA88E 18:23:54:203 3036 IRP_MJ_CLEANUP : 804FA88E 18:23:54:203 3036 IRP_MJ_CREATE_MAILSLOT : 804FA88E 18:23:54:203 3036 IRP_MJ_QUERY_SECURITY : 804FA88E 18:23:54:203 3036 IRP_MJ_SET_SECURITY : 804FA88E 18:23:54:203 3036 IRP_MJ_POWER : F8579C82 18:23:54:203 3036 IRP_MJ_SYSTEM_CONTROL : F857E99E 18:23:54:203 3036 IRP_MJ_DEVICE_CHANGE : 804FA88E 18:23:54:203 3036 IRP_MJ_QUERY_QUOTA : 804FA88E 18:23:54:203 3036 IRP_MJ_SET_QUOTA : 804FA88E 18:23:54:218 3036 C:\WINDOWS\system32\DRIVERS\disk.sys - Verdict: 1 18:23:54:218 3036 18:23:54:218 3036 Driver Name: Disk 18:23:54:218 3036 IRP_MJ_CREATE : F857DBB0 18:23:54:218 3036 IRP_MJ_CREATE_NAMED_PIPE : 804FA88E 18:23:54:218 3036 IRP_MJ_CLOSE : F857DBB0 18:23:54:218 3036 IRP_MJ_READ : F8577D1F 18:23:54:218 3036 IRP_MJ_WRITE : F8577D1F 18:23:54:218 3036 IRP_MJ_QUERY_INFORMATION : 804FA88E 18:23:54:218 3036 IRP_MJ_SET_INFORMATION : 804FA88E 18:23:54:218 3036 IRP_MJ_QUERY_EA : 804FA88E 18:23:54:218 3036 IRP_MJ_SET_EA : 804FA88E 18:23:54:218 3036 IRP_MJ_FLUSH_BUFFERS : F85782E2 18:23:54:218 3036 IRP_MJ_QUERY_VOLUME_INFORMATION : 804FA88E 18:23:54:218 3036 IRP_MJ_SET_VOLUME_INFORMATION : 804FA88E 18:23:54:218 3036 IRP_MJ_DIRECTORY_CONTROL : 804FA88E 18:23:54:218 3036 IRP_MJ_FILE_SYSTEM_CONTROL : 804FA88E 18:23:54:218 3036 IRP_MJ_DEVICE_CONTROL : F85783BB 18:23:54:218 3036 IRP_MJ_INTERNAL_DEVICE_CONTROL : F857BF28 18:23:54:218 3036 IRP_MJ_SHUTDOWN : F85782E2 18:23:54:218 3036 IRP_MJ_LOCK_CONTROL : 804FA88E 18:23:54:218 3036 IRP_MJ_CLEANUP : 804FA88E 18:23:54:218 3036 IRP_MJ_CREATE_MAILSLOT : 804FA88E 18:23:54:218 3036 IRP_MJ_QUERY_SECURITY : 804FA88E 18:23:54:218 3036 IRP_MJ_SET_SECURITY : 804FA88E 18:23:54:218 3036 IRP_MJ_POWER : F8579C82 18:23:54:218 3036 IRP_MJ_SYSTEM_CONTROL : F857E99E 18:23:54:218 3036 IRP_MJ_DEVICE_CHANGE : 804FA88E 18:23:54:218 3036 IRP_MJ_QUERY_QUOTA : 804FA88E 18:23:54:218 3036 IRP_MJ_SET_QUOTA : 804FA88E 18:23:54:234 3036 C:\WINDOWS\system32\DRIVERS\disk.sys - Verdict: 1 18:23:54:234 3036 18:23:54:234 3036 Driver Name: Disk 18:23:54:234 3036 IRP_MJ_CREATE : F857DBB0 18:23:54:234 3036 IRP_MJ_CREATE_NAMED_PIPE : 804FA88E 18:23:54:234 3036 IRP_MJ_CLOSE : F857DBB0 18:23:54:234 3036 IRP_MJ_READ : F8577D1F 18:23:54:234 3036 IRP_MJ_WRITE : F8577D1F 18:23:54:234 3036 IRP_MJ_QUERY_INFORMATION : 804FA88E 18:23:54:234 3036 IRP_MJ_SET_INFORMATION : 804FA88E 18:23:54:234 3036 IRP_MJ_QUERY_EA : 804FA88E 18:23:54:234 3036 IRP_MJ_SET_EA : 804FA88E 18:23:54:234 3036 IRP_MJ_FLUSH_BUFFERS : F85782E2 18:23:54:234 3036 IRP_MJ_QUERY_VOLUME_INFORMATION : 804FA88E 18:23:54:234 3036 IRP_MJ_SET_VOLUME_INFORMATION : 804FA88E 18:23:54:234 3036 IRP_MJ_DIRECTORY_CONTROL : 804FA88E 18:23:54:234 3036 IRP_MJ_FILE_SYSTEM_CONTROL : 804FA88E 18:23:54:234 3036 IRP_MJ_DEVICE_CONTROL : F85783BB 18:23:54:234 3036 IRP_MJ_INTERNAL_DEVICE_CONTROL : F857BF28 18:23:54:234 3036 IRP_MJ_SHUTDOWN : F85782E2 18:23:54:234 3036 IRP_MJ_LOCK_CONTROL : 804FA88E 18:23:54:234 3036 IRP_MJ_CLEANUP : 804FA88E 18:23:54:234 3036 IRP_MJ_CREATE_MAILSLOT : 804FA88E 18:23:54:234 3036 IRP_MJ_QUERY_SECURITY : 804FA88E 18:23:54:234 3036 IRP_MJ_SET_SECURITY : 804FA88E 18:23:54:234 3036 IRP_MJ_POWER : F8579C82 18:23:54:234 3036 IRP_MJ_SYSTEM_CONTROL : F857E99E 18:23:54:234 3036 IRP_MJ_DEVICE_CHANGE : 804FA88E 18:23:54:234 3036 IRP_MJ_QUERY_QUOTA : 804FA88E 18:23:54:234 3036 IRP_MJ_SET_QUOTA : 804FA88E 18:23:54:234 3036 C:\WINDOWS\system32\DRIVERS\disk.sys - Verdict: 1 18:23:54:234 3036 18:23:54:234 3036 Driver Name: Disk 18:23:54:234 3036 IRP_MJ_CREATE : F857DBB0 18:23:54:234 3036 IRP_MJ_CREATE_NAMED_PIPE : 804FA88E 18:23:54:234 3036 IRP_MJ_CLOSE : F857DBB0 18:23:54:234 3036 IRP_MJ_READ : F8577D1F 18:23:54:234 3036 IRP_MJ_WRITE : F8577D1F 18:23:54:234 3036 IRP_MJ_QUERY_INFORMATION : 804FA88E 18:23:54:234 3036 IRP_MJ_SET_INFORMATION : 804FA88E 18:23:54:234 3036 IRP_MJ_QUERY_EA : 804FA88E 18:23:54:234 3036 IRP_MJ_SET_EA : 804FA88E 18:23:54:234 3036 IRP_MJ_FLUSH_BUFFERS : F85782E2 18:23:54:234 3036 IRP_MJ_QUERY_VOLUME_INFORMATION : 804FA88E 18:23:54:234 3036 IRP_MJ_SET_VOLUME_INFORMATION : 804FA88E 18:23:54:234 3036 IRP_MJ_DIRECTORY_CONTROL : 804FA88E 18:23:54:234 3036 IRP_MJ_FILE_SYSTEM_CONTROL : 804FA88E 18:23:54:234 3036 IRP_MJ_DEVICE_CONTROL : F85783BB 18:23:54:234 3036 IRP_MJ_INTERNAL_DEVICE_CONTROL : F857BF28 18:23:54:234 3036 IRP_MJ_SHUTDOWN : F85782E2 18:23:54:234 3036 IRP_MJ_LOCK_CONTROL : 804FA88E 18:23:54:234 3036 IRP_MJ_CLEANUP : 804FA88E 18:23:54:234 3036 IRP_MJ_CREATE_MAILSLOT : 804FA88E 18:23:54:234 3036 IRP_MJ_QUERY_SECURITY : 804FA88E 18:23:54:234 3036 IRP_MJ_SET_SECURITY : 804FA88E 18:23:54:234 3036 IRP_MJ_POWER : F8579C82 18:23:54:234 3036 IRP_MJ_SYSTEM_CONTROL : F857E99E 18:23:54:234 3036 IRP_MJ_DEVICE_CHANGE : 804FA88E 18:23:54:234 3036 IRP_MJ_QUERY_QUOTA : 804FA88E 18:23:54:234 3036 IRP_MJ_SET_QUOTA : 804FA88E 18:23:54:234 3036 C:\WINDOWS\system32\DRIVERS\disk.sys - Verdict: 1 18:23:54:234 3036 18:23:54:234 3036 Driver Name: atapi 18:23:54:234 3036 IRP_MJ_CREATE : F84846F2 18:23:54:234 3036 IRP_MJ_CREATE_NAMED_PIPE : 804FA88E 18:23:54:234 3036 IRP_MJ_CLOSE : F84846F2 18:23:54:234 3036 IRP_MJ_READ : 804FA88E 18:23:54:234 3036 IRP_MJ_WRITE : 804FA88E 18:23:54:234 3036 IRP_MJ_QUERY_INFORMATION : 804FA88E 18:23:54:234 3036 IRP_MJ_SET_INFORMATION : 804FA88E 18:23:54:234 3036 IRP_MJ_QUERY_EA : 804FA88E 18:23:54:234 3036 IRP_MJ_SET_EA : 804FA88E 18:23:54:234 3036 IRP_MJ_FLUSH_BUFFERS : 804FA88E 18:23:54:234 3036 IRP_MJ_QUERY_VOLUME_INFORMATION : 804FA88E 18:23:54:234 3036 IRP_MJ_SET_VOLUME_INFORMATION : 804FA88E 18:23:54:234 3036 IRP_MJ_DIRECTORY_CONTROL : 804FA88E 18:23:54:234 3036 IRP_MJ_FILE_SYSTEM_CONTROL : 804FA88E 18:23:54:234 3036 IRP_MJ_DEVICE_CONTROL : F8484712 18:23:54:234 3036 IRP_MJ_INTERNAL_DEVICE_CONTROL : F8480852 18:23:54:234 3036 IRP_MJ_SHUTDOWN : 804FA88E 18:23:54:234 3036 IRP_MJ_LOCK_CONTROL : 804FA88E 18:23:54:234 3036 IRP_MJ_CLEANUP : 804FA88E 18:23:54:234 3036 IRP_MJ_CREATE_MAILSLOT : 804FA88E 18:23:54:234 3036 IRP_MJ_QUERY_SECURITY : 804FA88E 18:23:54:234 3036 IRP_MJ_SET_SECURITY : 804FA88E 18:23:54:234 3036 IRP_MJ_POWER : F848473C 18:23:54:234 3036 IRP_MJ_SYSTEM_CONTROL : F848B336 18:23:54:234 3036 IRP_MJ_DEVICE_CHANGE : 804FA88E 18:23:54:234 3036 IRP_MJ_QUERY_QUOTA : 804FA88E 18:23:54:234 3036 IRP_MJ_SET_QUOTA : 804FA88E 18:23:54:281 3036 C:\WINDOWS\system32\DRIVERS\ATAPI.SYS - Verdict: 1 18:23:54:281 3036 18:23:54:281 3036 Driver Name: atapi 18:23:54:281 3036 IRP_MJ_CREATE : F84846F2 18:23:54:281 3036 IRP_MJ_CREATE_NAMED_PIPE : 804FA88E 18:23:54:281 3036 IRP_MJ_CLOSE : F84846F2 18:23:54:281 3036 IRP_MJ_READ : 804FA88E 18:23:54:281 3036 IRP_MJ_WRITE : 804FA88E 18:23:54:281 3036 IRP_MJ_QUERY_INFORMATION : 804FA88E 18:23:54:281 3036 IRP_MJ_SET_INFORMATION : 804FA88E 18:23:54:281 3036 IRP_MJ_QUERY_EA : 804FA88E 18:23:54:281 3036 IRP_MJ_SET_EA : 804FA88E 18:23:54:281 3036 IRP_MJ_FLUSH_BUFFERS : 804FA88E 18:23:54:281 3036 IRP_MJ_QUERY_VOLUME_INFORMATION : 804FA88E 18:23:54:281 3036 IRP_MJ_SET_VOLUME_INFORMATION : 804FA88E 18:23:54:281 3036 IRP_MJ_DIRECTORY_CONTROL : 804FA88E 18:23:54:281 3036 IRP_MJ_FILE_SYSTEM_CONTROL : 804FA88E 18:23:54:281 3036 IRP_MJ_DEVICE_CONTROL : F8484712 18:23:54:281 3036 IRP_MJ_INTERNAL_DEVICE_CONTROL : F8480852 18:23:54:281 3036 IRP_MJ_SHUTDOWN : 804FA88E 18:23:54:281 3036 IRP_MJ_LOCK_CONTROL : 804FA88E 18:23:54:281 3036 IRP_MJ_CLEANUP : 804FA88E 18:23:54:281 3036 IRP_MJ_CREATE_MAILSLOT : 804FA88E 18:23:54:281 3036 IRP_MJ_QUERY_SECURITY : 804FA88E 18:23:54:281 3036 IRP_MJ_SET_SECURITY : 804FA88E 18:23:54:281 3036 IRP_MJ_POWER : F848473C 18:23:54:281 3036 IRP_MJ_SYSTEM_CONTROL : F848B336 18:23:54:281 3036 IRP_MJ_DEVICE_CHANGE : 804FA88E 18:23:54:281 3036 IRP_MJ_QUERY_QUOTA : 804FA88E 18:23:54:281 3036 IRP_MJ_SET_QUOTA : 804FA88E 18:23:54:296 3036 C:\WINDOWS\system32\DRIVERS\ATAPI.SYS - Verdict: 1 18:23:54:296 3036 18:23:54:296 3036 Completed 18:23:54:296 3036 18:23:54:296 3036 Results: 18:23:54:296 3036 Memory objects infected / cured / cured on reboot: 0 / 0 / 0 18:23:54:296 3036 Registry objects infected / cured / cured on reboot: 0 / 0 / 0 18:23:54:296 3036 File objects infected / cured / cured on reboot: 0 / 0 / 0 18:23:54:296 3036 18:23:54:296 3036 fclose_ex: Trying to close file C:\WINDOWS\system32\config\system 18:23:54:328 3036 fclose_ex: Trying to close file C:\WINDOWS\system32\config\software 18:23:54:328 3036 KLMD(ARK) unloaded successfully The computer seems to be running fine, haven't had any reacurances of the just in time debugging window. The one thing I do notice is that it takes an awfully long time to start up, other that that it seems just fine. Thanks fo all you do, Spidey
Hello spidey

Please go to http://virusscan.jotti.org, click on Browse, and upload the following file for analysis:

c:\windows\system32\drivers\hsiwouul.sys

If jotti is busy try http://virscan.org/

Please post the results.
Hi Mowman, Here's the results: Filename: hsiwouul.sys Status: Scan finished. 0 out of 20 scanners reported malware. Scan taken on: Sat 8 May 2010 17:49:48 (CET) Permalink Additional info File size: 96512 bytes Filetype: PE32 executable for MS Windows (native) Intel 80386 32-bit MD5: 9f3a2f5aa6875c72bf062c712cfa2674 SHA1: a719156e8ad67456556a02c34e762944234e7a44 Packer (Kaspersky): PE_Patch ——————————————————————————- Thanks, Spidey

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI