This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Trojan horse Generic19.BNIE?

14 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Don't know if I'm actually infected with anything, but after having something happen only a few months back, I just want to check to be sure.
AVG detected this Trojan today, yet I hadn't even used the program. I think what I did right before the AVG threat pop up, was opening the Control Panel.

I ended up downloading OTL, HijackThis and DDS, but will only post OTL now. If hijackthis and/or dds is preferred, I can post those logs too.

OTL

OTL logfile created on: 10/20/2010 2:36:40 PM - Run 1
OTL by OldTimer - Version 3.2.16.0 Folder = C:\Documents and Settings\r\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1,023.00 Mb Total Physical Memory | 523.00 Mb Available Physical Memory | 51.00% Memory free
2.00 Gb Paging File | 2.00 Gb Available in Paging File | 84.00% Paging File free
Paging file location(s): C:\pagefile.sys 1536 3072 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 29.29 Gb Total Space | 11.50 Gb Free Space | 39.27% Space Free | Partition Type: NTFS
Drive D: | 82.49 Gb Total Space | 18.21 Gb Free Space | 22.08% Space Free | Partition Type: NTFS

Computer Name: R-EA6D203B44404 | User Name: r | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\r\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files\AVG\AVG9\avgtray.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\avgnsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\avgrsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\avgcsrvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\avgchsvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Dell Photo AIO Printer 962\dlbxmon.exE (Dell)
PRC - C:\WINDOWS\system32\dlbxcoms.exe (Dell)
PRC - C:\Program Files\Analog Devices\SoundMAX\SMax4.exe (Analog Devices, Inc.)
PRC - C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe (Analog Devices, Inc.)
PRC - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe (Analog Devices, Inc.)


========== Modules (SafeList) ==========

MOD - C:\Documents and Settings\r\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\WINDOWS\system32\msscript.ocx (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV - (HidServ) – C:\WINDOWS\System32\hidserv.dll File not found
SRV - (getPlusHelper) getPlus® – C:\Program Files\NOS\bin\getPlus_Helper.dll File not found
SRV - (avg9wd) – C:\Program Files\AVG\AVG9\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (dlbx_device) – C:\WINDOWS\System32\dlbxcoms.exe (Dell)
SRV - (SoundMAX Agent Service (default)) – C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe (Analog Devices, Inc.)


========== Driver Services (SafeList) ==========

DRV - (scsk5) – C:\WINDOWS\System32\drivers\scsk5.sys File not found
DRV - (NOWMEMDF) – C:\WINDOWS\System32\NOWMEMDF.sys File not found
DRV - (Lbd) – C:\WINDOWS\System32\DRIVERS\Lbd.sys File not found
DRV - (GEARAspiWDM) – C:\WINDOWS\System32\Drivers\GEARAspiWDM.sys File not found
DRV - (catchme) – C:\DOCUME~1\r\LOCALS~1\Temp\catchme.sys File not found
DRV - (AvgTdiX) – C:\WINDOWS\System32\Drivers\avgtdix.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgLdx86) – C:\WINDOWS\System32\Drivers\avgldx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgMfx86) – C:\WINDOWS\System32\Drivers\avgmfx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (nm) – C:\WINDOWS\system32\drivers\nmnt.sys (Microsoft Corporation)
DRV - (nv) – C:\WINDOWS\system32\drivers\nv4_mini.sys (NVIDIA Corporation)
DRV - (EL2000) – C:\WINDOWS\system32\drivers\EL2K_XP.sys (3Com Corporation)
DRV - (MidiSyn) – C:\WINDOWS\system32\drivers\MidiSyn.sys (Analog Devices Inc)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========


IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.search.defaultenginename: "Yahoo"
FF - prefs.js..browser.search.order.1: "Yahoo"
FF - prefs.js..browser.search.param.yahoo-fr: "megaup"
FF - prefs.js..browser.search.param.yahoo-fr-cjkt: "megaup"
FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://mail.google.com/"
FF - prefs.js..extensions.enabledItems: [removed]:1.1.6
FF - prefs.js..extensions.enabledItems: [removed]:3.5
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: [removed]:[removed]
FF - prefs.js..extensions.enabledItems: [removed]:1.76
FF - prefs.js..extensions.enabledItems: {3f963a5b-e555-4543-90e2-c3908898db71}:9.0.0.855
FF - prefs.js..extensions.enabledItems: {99210d54-6321-41e8-bd1b-2b4c55874efb}:1.16
FF - prefs.js..extensions.enabledItems: {a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7}:20100908
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21
FF - prefs.js..keyword.URL: "http://ca.search.yahoo.com/search?ei=utf-8&fr;=megaup&p;="

FF - HKLM\software\mozilla\Firefox\Extensions\\{3f963a5b-e555-4543-90e2-c3908898db71}: C:\Program Files\AVG\AVG9\Firefox [2010/09/23 12:14:49 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.11\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/10/20 10:25:46 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.11\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/10/20 10:25:46 | 000,000,000 | —D | M]

[2009/03/30 19:50:19 | 000,000,000 | —D | M] – C:\Documents and Settings\r\Application Data\Mozilla\Extensions
[2010/10/18 11:39:37 | 000,000,000 | —D | M] – C:\Documents and Settings\r\Application Data\Mozilla\Firefox\Profiles\ltwnytn6.default\extensions
[2010/09/20 02:42:12 | 000,000,000 | —D | M] (FoxyTunes) – C:\Documents and Settings\r\Application Data\Mozilla\Firefox\Profiles\ltwnytn6.default\extensions\{463F6CA5-EE3C-4be1-B7E6-7FEE11953374}
[2010/04/24 01:50:18 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\r\Application Data\Mozilla\Firefox\Profiles\ltwnytn6.default\extensions\{99210d54-6321-41e8-bd1b-2b4c55874efb}
[2010/09/11 12:22:37 | 000,000,000 | —D | M] (WOT) – C:\Documents and Settings\r\Application Data\Mozilla\Firefox\Profiles\ltwnytn6.default\extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7}
[2010/03/13 21:10:15 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\r\Application Data\Mozilla\Firefox\Profiles\ltwnytn6.default\extensions\{a81bafeb-b6ed-4501-aa17-15a2b3857e56}
[2010/03/01 19:08:27 | 000,000,000 | —D | M] – C:\Documents and Settings\r\Application Data\Mozilla\Firefox\Profiles\ltwnytn6.default\extensions\[removed]
[2010/08/15 21:03:08 | 000,000,000 | —D | M] – C:\Documents and Settings\r\Application Data\Mozilla\Firefox\Profiles\ltwnytn6.default\extensions\[removed]
[2010/03/01 19:08:14 | 000,000,000 | —D | M] – C:\Documents and Settings\r\Application Data\Mozilla\Firefox\Profiles\ltwnytn6.default\extensions\[removed]
[2007/10/18 04:35:05 | 000,000,000 | —D | M] – C:\Documents and Settings\r\Application Data\Mozilla\Firefox\Profiles\ltwnytn6.default\extensions\[removed]
[2010/06/27 13:10:45 | 000,000,000 | —D | M] – C:\Documents and Settings\r\Application Data\Mozilla\Firefox\Profiles\ltwnytn6.default\extensions\[removed]
[2008/09/25 01:55:04 | 000,002,280 | —- | M] () – C:\Documents and Settings\r\Application Data\Mozilla\Firefox\Profiles\ltwnytn6.default\searchplugins\6lpve-c5.xml
[2008/11/24 11:05:13 | 000,001,030 | —- | M] () – C:\Documents and Settings\r\Application Data\Mozilla\Firefox\Profiles\ltwnytn6.default\searchplugins\sogou.xml
[2010/10/18 11:39:37 | 000,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions
[2010/08/15 23:03:09 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
[2010/07/17 05:00:04 | 000,423,656 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll
[2005/12/05 22:31:00 | 000,114,688 | —- | M] () – C:\Program Files\Mozilla Firefox\plugins\npmozax.dll

O1 HOSTS File: ([2010/07/15 09:27:39 | 000,000,027 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG9\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (IeMonitorBho Class) - {bf00e119-21a3-4fd1-b178-3b8537e75c92} - C:\Program Files\Megaupload\Mega Manager\MegaIEMn.dll (Megaupload Limited)
O2 - BHO: (Nero Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask.com)
O3 - HKLM\..\Toolbar: (Veoh Web Player Video Finder) - {0FBB9689-D3D7-4f7a-A2E2-585B10099BFC} - C:\Program Files\Veoh Networks\VeohWebPlayer\VeohIEToolbar.dll (Veoh Networks Inc)
O3 - HKLM\..\Toolbar: (Nero Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask.com)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {C55BBCD6-41AD-48AD-9953-3609C48EACC7} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (Nero Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask.com)
O4 - HKLM..\Run: [AVG9_TRAY] C:\Program Files\AVG\AVG9\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [DLBXCATS] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\DLBXtime.DLL ()
O4 - HKLM..\Run: [dlbxmon.exe] C:\Program Files\Dell Photo AIO Printer 962\dlbxmon.exe (Dell)
O4 - HKLM..\Run: [IMJPMIG8.1] C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [SoundMax] C:\Program Files\Analog Devices\SoundMAX\smax4.exe (Analog Devices, Inc.)
O4 - HKLM..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe (Analog Devices, Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (Adobe Systems, Inc.)
O4 - Startup: C:\Documents and Settings\r\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE ()
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: Download Link Using Mega Manager… - C:\Program Files\Megaupload\Mega Manager\mm_file.htm ()
O16 - DPF: {00000055-9980-0010-8000-00AA00389B71} http://codecs.microsoft.com/codecs/i386/fhg.CAB (Reg Error: Key error.)
O16 - DPF: {0349EF81-B9C1-4B97-86F7-7B931D0E2532} http://sticube.clubbox.co.kr/sticubeupdate…NowStarter2.cab (NowStarter2 Control)
O16 - DPF: {049A470D-F818-4E34-B14D-E4E237DADCF8} http://www.shockwave.com/content/fashionda…eb.1.0.0.21.cab (CPlayFirstFashionDasControl Object)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://download.macromedia.com/pub/shockwa…ash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG9\avgpp.dll (AVG Technologies CZ, s.r.o.)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\avgrsstarter: DllName - avgrsstx.dll - C:\WINDOWS\System32\avgrsstx.dll (AVG Technologies CZ, s.r.o.)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2007/06/11 22:11:50 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O33 - MountPoints2\{8db3a5c9-6f7b-11df-bb87-000c6eee2122}\Shell\AutoRun\command - "" = G:\setup.exe – File not found
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: 6to4 - File not found
NetSvcs: HidServ - C:\WINDOWS\System32\hidserv.dll File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found

Drivers32: msacm.ac3acm - C:\WINDOWS\System32\ac3acm.acm (fccHandler)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.lameacm - C:\WINDOWS\System32\lameACM.acm (http://www.mp3dev.org/)
Drivers32: vidc.CSCD - C:\WINDOWS\System32\camcodec.dll (RenderSoft Software)
Drivers32: VIDC.DIVX - C:\WINDOWS\System32\divx.dll (DivX, Inc.)
Drivers32: VIDC.FFDS - C:\WINDOWS\System32\ff_vfw.dll ()
Drivers32: VIDC.wmv3 - C:\WINDOWS\System32\wmv9vcm.dll (Microsoft Corporation)
Drivers32: VIDC.X264 - C:\WINDOWS\System32\x264vfw.dll ()
Drivers32: VIDC.XVID - C:\WINDOWS\System32\xvidvfw.dll ()
Drivers32: VIDC.YV12 - C:\WINDOWS\System32\yv12vfw.dll (www.helixcommunity.org)

CREATERESTOREPOINT
Error starting restore point: System Restore is disabled.
Error closing restore point: System Restore is disabled.

========== Files/Folders - Created Within 30 Days ==========

[2010/10/20 14:34:01 | 000,388,608 | —- | C] (Trend Micro Inc.) – C:\Documents and Settings\r\Desktop\HiJackThis.exe
[2010/10/20 14:32:59 | 000,575,488 | —- | C] (OldTimer Tools) – C:\Documents and Settings\r\Desktop\OTL.exe
[2010/10/20 13:57:23 | 000,000,000 | —D | C] – C:\Program Files\LG Electronics
[2010/10/18 16:10:47 | 000,000,000 | —D | C] – D:\My Documents\jdownload-20091102-bin
[2010/10/18 16:06:51 | 000,000,000 | —D | C] – D:\My Documents\jdownload-20091102-src
[2010/10/16 14:03:15 | 000,000,000 | -HSD | C] – C:\Config.Msi
[2010/10/16 13:50:10 | 000,000,000 | —D | C] – C:\Program Files\Saezuri
[2010/10/14 14:34:34 | 000,000,000 | —D | C] – D:\My Documents\splatter_01
[2010/10/14 14:34:34 | 000,000,000 | —D | C] – D:\My Documents\__MACOSX
[2010/10/09 21:43:43 | 000,000,000 | —D | C] – C:\Documents and Settings\r\My Documents
[2010/10/04 15:53:38 | 000,000,000 | —D | C] – D:\My Documents\Coffee House OST
[2010/09/23 15:02:15 | 000,000,000 | —D | C] – D:\My Documents\miss A - Bad But Good

========== Files - Modified Within 30 Days ==========

[2010/10/20 14:34:12 | 000,359,929 | —- | M] () – C:\Documents and Settings\r\Desktop\dds.scr
[2010/10/20 14:34:02 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Documents and Settings\r\Desktop\HiJackThis.exe
[2010/10/20 14:32:59 | 000,575,488 | —- | M] (OldTimer Tools) – C:\Documents and Settings\r\Desktop\OTL.exe
[2010/10/20 14:10:40 | 1072,484,352 | -HS- | M] () – C:\hiberfil.sys
[2010/10/20 14:10:40 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2010/10/20 14:01:00 | 000,000,226 | —- | M] () – C:\WINDOWS\tasks\Scheduled Update for Ask Toolbar.job
[2010/10/20 13:25:54 | 000,093,184 | —- | M] () – C:\Documents and Settings\r\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/10/20 10:29:05 | 066,614,401 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\incavi.avm
[2010/10/18 16:10:41 | 000,111,908 | —- | M] () – D:\My Documents\jdownload-20091102-bin.zip
[2010/10/18 16:05:52 | 000,758,913 | —- | M] () – D:\My Documents\jdownload-20091102-src.zip
[2010/10/18 13:13:36 | 000,002,283 | —- | M] () – C:\Documents and Settings\r\Application Data\Microsoft\Internet Explorer\Quick Launch\Skype.lnk
[2010/10/16 14:50:20 | 002,910,584 | —- | M] () – C:\Documents and Settings\r\Desktop\178327187.jpg
[2010/10/16 14:07:33 | 000,148,672 | —- | M] () – C:\Documents and Settings\r\Desktop\178249436.jpg
[2010/10/15 23:46:23 | 000,013,646 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2010/10/14 14:34:27 | 001,425,937 | —- | M] () – D:\My Documents\splatter_01.zip
[2010/10/11 19:44:41 | 366,729,096 | —- | M] () – C:\Documents and Settings\r\Desktop\LUX 2.04.avi
[2010/10/09 21:44:19 | 000,001,729 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Adobe Reader 9.lnk
[2010/10/09 14:18:04 | 000,286,589 | —- | M] () – D:\My Documents\coupon_en.pdf
[2010/10/07 20:56:35 | 000,142,804 | —- | M] () – C:\Documents and Settings\r\Desktop\PrintCoupon.pdf
[2010/10/05 11:46:27 | 000,000,723 | —- | M] () – C:\WINDOWS\dellstat.ini
[2010/10/04 15:53:27 | 050,490,668 | —- | M] () – D:\My Documents\Coffe House OST.rar
[2010/09/23 16:17:56 | 000,234,157 | —- | M] () – D:\My Documents\Live Clean Coupon.pdf
[2010/09/23 14:16:29 | 031,312,395 | —- | M] () – D:\My Documents\miss a - Bad But Good.rar
[2010/09/20 15:56:27 | 009,751,909 | —- | M] () – D:\My Documents\02 High Kick Through the Roof OST - You Are My Girl.mp3

========== Files Created - No Company Name ==========

[2010/10/20 14:34:11 | 000,359,929 | —- | C] () – C:\Documents and Settings\r\Desktop\dds.scr
[2010/10/18 16:10:41 | 000,111,908 | —- | C] () – D:\My Documents\jdownload-20091102-bin.zip
[2010/10/18 16:05:50 | 000,758,913 | —- | C] () – D:\My Documents\jdownload-20091102-src.zip
[2010/10/16 14:50:18 | 002,910,584 | —- | C] () – C:\Documents and Settings\r\Desktop\178327187.jpg
[2010/10/16 14:07:32 | 000,148,672 | —- | C] () – C:\Documents and Settings\r\Desktop\178249436.jpg
[2010/10/14 14:34:25 | 001,425,937 | —- | C] () – D:\My Documents\splatter_01.zip
[2010/10/11 19:36:19 | 366,729,096 | —- | C] () – C:\Documents and Settings\r\Desktop\LUX 2.04.avi
[2010/10/09 21:44:19 | 000,001,729 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Adobe Reader 9.lnk
[2010/10/09 14:18:01 | 000,286,589 | —- | C] () – D:\My Documents\coupon_en.pdf
[2010/10/07 20:56:35 | 000,142,804 | —- | C] () – C:\Documents and Settings\r\Desktop\PrintCoupon.pdf
[2010/10/04 15:51:26 | 050,490,668 | —- | C] () – D:\My Documents\Coffe House OST.rar
[2010/09/23 16:17:56 | 000,234,157 | —- | C] () – D:\My Documents\Live Clean Coupon.pdf
[2010/09/23 14:15:22 | 031,312,395 | —- | C] () – D:\My Documents\miss a - Bad But Good.rar
[2010/09/20 15:53:22 | 009,751,909 | —- | C] () – D:\My Documents\02 High Kick Through the Roof OST - You Are My Girl.mp3
[2010/05/14 13:09:17 | 000,077,824 | —- | C] () – C:\WINDOWS\System32\nod.dll
[2010/05/14 13:08:36 | 000,000,634 | —- | C] () – C:\WINDOWS\System32\fscflist.ini
[2010/05/14 13:08:35 | 000,000,080 | —- | C] () – C:\WINDOWS\System32\fscagent.ini
[2010/05/09 21:34:28 | 000,093,184 | —- | C] () – C:\Documents and Settings\r\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/08/25 14:20:25 | 000,000,038 | —- | C] () – C:\WINDOWS\avisplitter.ini
[2009/08/25 14:20:23 | 002,378,752 | —- | C] () – C:\WINDOWS\System32\x264vfw.dll
[2009/08/25 14:20:23 | 000,881,664 | —- | C] () – C:\WINDOWS\System32\xvidcore.dll
[2009/08/25 14:20:23 | 000,205,824 | —- | C] () – C:\WINDOWS\System32\xvidvfw.dll
[2009/08/25 14:20:22 | 003,596,288 | —- | C] () – C:\WINDOWS\System32\qt-dx331.dll
[2009/08/25 14:20:20 | 000,085,504 | —- | C] () – C:\WINDOWS\System32\ff_vfw.dll
[2009/07/07 20:58:12 | 000,000,040 | —- | C] () – C:\WINDOWS\nero.INI
[2008/10/26 18:53:18 | 000,000,050 | —- | C] () – C:\WINDOWS\MegaManager.INI
[2008/08/08 08:40:32 | 000,092,672 | —- | C] () – C:\WINDOWS\System32\ybimuujqma.dll
[2008/07/14 15:53:56 | 000,000,218 | —- | C] () – C:\WINDOWS\System32\adionalcoo.ini
[2008/04/16 23:00:38 | 000,000,032 | —- | C] () – C:\Documents and Settings\All Users\Application Data\ezsid.dat
[2007/06/30 02:20:01 | 000,002,540 | —- | C] () – C:\Documents and Settings\All Users\Application Data\QTSBandwidthCache
[2007/06/29 16:44:29 | 000,000,723 | —- | C] () – C:\WINDOWS\dellstat.ini
[2007/06/29 16:42:54 | 000,139,264 | —- | C] () – C:\WINDOWS\System32\dlbxins.dll
[2007/06/29 16:42:54 | 000,098,304 | —- | C] () – C:\WINDOWS\System32\dlbxinsr.dll
[2007/06/29 16:42:53 | 000,040,960 | —- | C] () – C:\WINDOWS\System32\dlbxvs.dll
[2007/06/29 16:42:51 | 000,069,632 | —- | C] () – C:\WINDOWS\System32\dlbxcu.dll
[2007/06/29 16:42:51 | 000,032,768 | —- | C] () – C:\WINDOWS\System32\dlbxcur.dll
[2007/06/29 16:42:50 | 000,397,312 | —- | C] () – C:\WINDOWS\System32\dlbxutil.dll
[2007/06/29 16:42:49 | 000,176,128 | —- | C] () – C:\WINDOWS\System32\dlbxinsb.dll
[2007/06/29 16:42:49 | 000,135,168 | —- | C] () – C:\WINDOWS\System32\dlbxjswr.dll
[2007/06/29 16:42:49 | 000,077,824 | —- | C] () – C:\WINDOWS\System32\dlbxcub.dll
[2007/06/26 19:28:04 | 000,061,440 | —- | C] () – C:\WINDOWS\System32\KTxtLog.dll
[2007/06/26 19:10:12 | 000,106,496 | —- | C] () – C:\WINDOWS\System32\KNetClient.dll
[2007/06/26 19:08:00 | 000,065,536 | —- | C] () – C:\WINDOWS\System32\KCharUtil.dll
[2007/06/13 23:53:11 | 000,000,116 | —- | C] () – C:\WINDOWS\NeroDigital.ini
[2007/06/13 00:42:17 | 000,000,000 | —- | C] () – C:\WINDOWS\vpc32.INI
[2007/06/11 22:43:18 | 000,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2007/06/11 22:22:15 | 000,003,766 | —- | C] () – C:\WINDOWS\Ascd_tmp.ini
[2007/06/11 22:22:13 | 000,005,824 | —- | C] () – C:\WINDOWS\System32\drivers\ASUSHWIO.SYS
[2007/06/11 14:58:54 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2007/05/25 14:23:56 | 000,000,016 | —- | C] () – C:\WINDOWS\System32\ver.ini
[2002/12/31 08:00:00 | 000,002,695 | —- | C] () – C:\WINDOWS\System32\OUTLPERF.INI
[2002/10/15 18:54:04 | 000,168,448 | —- | C] () – C:\WINDOWS\System32\unrar.dll

========== LOP Check ==========

[2010/03/13 21:01:10 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\avg9
[2008/10/20 14:57:15 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\EmailNotifier
[2009/04/12 00:01:22 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\GameHouse
[2007/09/13 15:14:46 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Last.fm
[2008/10/20 14:57:15 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Megaupload
[2007/10/09 00:17:50 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PlayFirst
[2009/04/12 03:59:33 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Zylom
[2009/07/08 19:36:11 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
[2010/06/10 18:48:30 | 000,000,000 | —D | M] – C:\Documents and Settings\r\Application Data\Aegisub
[2010/03/13 21:47:11 | 000,000,000 | —D | M] – C:\Documents and Settings\r\Application Data\AskToolbar
[2010/05/15 17:03:41 | 000,000,000 | —D | M] – C:\Documents and Settings\r\Application Data\de.makesoft.twhirl.0EA062BC275E7ED1E6EC3762EFFD73C7158ADF33.1
[2010/08/09 10:43:57 | 000,000,000 | —D | M] – C:\Documents and Settings\r\Application Data\ElevatedDiagnostics
[2008/09/15 00:39:26 | 000,000,000 | —D | M] – C:\Documents and Settings\r\Application Data\GrabPro
[2010/05/15 18:46:02 | 000,000,000 | —D | M] – C:\Documents and Settings\r\Application Data\jp.playwell.Saezuri.58F200D7EEA7AA1DF3962E867638EFEED92471BE.1
[2009/04/21 20:13:09 | 000,000,000 | —D | M] – C:\Documents and Settings\r\Application Data\Megaupload
[2010/06/01 23:36:46 | 000,000,000 | —D | M] – C:\Documents and Settings\r\Application Data\Orbit
[2007/10/09 00:17:50 | 000,000,000 | —D | M] – C:\Documents and Settings\r\Application Data\PlayFirst
[2008/08/21 21:40:25 | 000,000,000 | —D | M] – C:\Documents and Settings\r\Application Data\RapidCRC
[2010/07/18 12:16:30 | 000,000,000 | —D | M] – C:\Documents and Settings\r\Application Data\uTorrent
[2010/10/20 14:01:00 | 000,000,226 | —- | M] () – C:\WINDOWS\Tasks\Scheduled Update for Ask Toolbar.job

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2009/04/28 01:19:19 | 000,010,174 | —- | M] () – C:\aaw7boot.log
[2007/06/11 22:11:50 | 000,000,000 | —- | M] () – C:\AUTOEXEC.BAT
[2007/06/11 22:06:25 | 000,000,211 | —- | M] () – C:\Boot.bak
[2010/07/15 09:19:18 | 000,000,281 | RHS- | M] () – C:\boot.ini
[2004/08/03 23:00:00 | 000,260,272 | —- | M] () – C:\cmldr
[2007/06/11 22:11:50 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2010/07/13 18:03:55 | 000,120,384 | —- | M] () – C:\dlbx.log
[2009/12/02 15:15:54 | 000,001,733 | —- | M] () – C:\dlbxscan.log
[2010/10/20 14:10:40 | 1072,484,352 | -HS- | M] () – C:\hiberfil.sys
[2007/06/11 22:11:50 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2008/07/28 00:25:42 | 000,000,371 | -H– | M] () – C:\IPH.PH
[2007/06/11 22:11:50 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2004/08/04 08:00:00 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2010/07/15 14:02:52 | 000,250,048 | RHS- | M] () – C:\ntldr
[2010/10/20 14:10:39 | 1610,612,736 | -HS- | M] () – C:\pagefile.sys
[2007/10/09 02:50:55 | 000,087,669 | —- | M] () – C:\playground.log
[2007/07/06 23:57:05 | 000,000,172 | —- | M] () – C:\setupfax.log

< %systemroot%\Fonts\*.com >

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2007/06/11 22:11:24 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2004/12/16 11:15:10 | 000,073,728 | —- | M] () – C:\WINDOWS\system32\spool\prtprocs\w32x86\dlbxPP5C.DLL
[2008/07/06 08:06:10 | 000,089,088 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2002/12/31 08:00:00 | 000,025,840 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\mdippr.dll
[2008/07/06 06:50:03 | 000,597,504 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >
[2007/06/11 14:56:52 | 000,094,208 | —- | M] () – C:\WINDOWS\system32\config\default.sav
[2007/06/11 14:56:52 | 000,659,456 | —- | M] () – C:\WINDOWS\system32\config\software.sav
[2007/06/11 14:56:52 | 000,897,024 | —- | M] () – C:\WINDOWS\system32\config\system.sav

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
[2010/07/15 14:09:12 | 000,000,272 | -HS- | M] () – C:\Documents and Settings\All Users\Start Menu\desktop.ini

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2010/07/15 16:01:19 | 000,000,119 | -HS- | M] () – C:\Documents and Settings\r\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini
[2007/06/11 22:19:53 | 000,000,079 | —- | M] () – C:\Documents and Settings\r\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf

< %USERPROFILE%\Desktop\*.exe >
[2010/08/03 14:37:04 | 000,791,393 | —- | M] (Lars Hederer ) – C:\Documents and Settings\r\Desktop\erunt-setup.exe
[2010/10/20 14:34:02 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Documents and Settings\r\Desktop\HiJackThis.exe
[2000/11/15 09:21:16 | 000,178,688 | —- | M] () – C:\Documents and Settings\r\Desktop\hjsplit.exe
[2010/08/09 10:32:39 | 000,554,256 | —- | M] (Microsoft Corporation) – C:\Documents and Settings\r\Desktop\Mats_Run.dvd.exe
[2010/10/20 14:32:59 | 000,575,488 | —- | M] (OldTimer Tools) – C:\Documents and Settings\r\Desktop\OTL.exe
[2010/08/03 14:04:08 | 000,446,464 | —- | M] (OldTimer Tools) – C:\Documents and Settings\r\Desktop\TFC.exe

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2010-08-16 00:49:51

========== Files - Unicode (All) ==========
[2010/09/16 20:17:11 | 005,270,849 | —- | M] ()(D:\My Documents\01 Cyrano Agency OST - ?????? (It Was You).mp3) – D:\My Documents\01 Cyrano Agency OST - 당신이었군요 (It Was You).mp3
[2010/09/16 20:17:04 | 005,270,849 | —- | C] ()(D:\My Documents\01 Cyrano Agency OST - ?????? (It Was You).mp3) – D:\My Documents\01 Cyrano Agency OST - 당신이었군요 (It Was You).mp3
[2010/09/16 18:15:29 | 004,627,011 | —- | M] ()(D:\My Documents\02 Cyrano Agency OST - ??? ???? (I went to Cheonggyesan Mt.).mp3) – D:\My Documents\02 Cyrano Agency OST - 청계산 가버렸네 (I went to Cheonggyesan Mt.).mp3
[2010/09/16 18:15:25 | 004,627,011 | —- | C] ()(D:\My Documents\02 Cyrano Agency OST - ??? ???? (I went to Cheonggyesan Mt.).mp3) – D:\My Documents\02 Cyrano Agency OST - 청계산 가버렸네 (I went to Cheonggyesan Mt.).mp3
[2010/05/18 17:39:17 | 004,012,812 | —- | M] ()(D:\My Documents\05 ???? ???.mp3) – D:\My Documents\05 포기하지 말아요.mp3
[2010/05/18 17:31:20 | 004,012,812 | —- | C] ()(D:\My Documents\05 ???? ???.mp3) – D:\My Documents\05 포기하지 말아요.mp3
[2009/10/11 13:18:48 | 000,000,000 | —D | M](D:\My Documents\???TP) – D:\My Documents\가수별TP
[2009/10/11 13:18:48 | 000,000,000 | —D | C](D:\My Documents\???TP) – D:\My Documents\가수별TP
[2009/09/13 16:31:26 | 000,000,000 | —D | M](D:\My Documents\????0913) – D:\My Documents\인기가요0913
[2009/09/13 16:31:26 | 000,000,000 | —D | C](D:\My Documents\????0913) – D:\My Documents\인기가요0913
[2009/09/12 14:50:19 | 000,000,000 | —D | M](D:\My Documents\??TP) – D:\My Documents\개별TP
[2009/09/12 14:50:19 | 000,000,000 | —D | C](D:\My Documents\??TP) – D:\My Documents\개별TP
[2009/09/09 18:50:06 | 201,828,352 | —- | M] ()(D:\My Documents\090804.OPPO?????Part5.????[1024][????].mpg) – D:\My Documents\090804.OPPO音乐狂欢夜Part5.爱你爱你[1024][追光韩庚].mpg
[2009/09/09 16:42:26 | 201,828,352 | —- | C] ()(D:\My Documents\090804.OPPO?????Part5.????[1024][????].mpg) – D:\My Documents\090804.OPPO音乐狂欢夜Part5.爱你爱你[1024][追光韩庚].mpg

< End of report >

Extras

OTL Extras logfile created on: 10/20/2010 2:36:40 PM - Run 1
OTL by OldTimer - Version 3.2.16.0 Folder = C:\Documents and Settings\r\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1,023.00 Mb Total Physical Memory | 523.00 Mb Available Physical Memory | 51.00% Memory free
2.00 Gb Paging File | 2.00 Gb Available in Paging File | 84.00% Paging File free
Paging file location(s): C:\pagefile.sys 1536 3072 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 29.29 Gb Total Space | 11.50 Gb Free Space | 39.27% Space Free | Partition Type: NTFS
Drive D: | 82.49 Gb Total Space | 18.21 Gb Free Space | 22.08% Space Free | Partition Type: NTFS

Computer Name: R-EA6D203B44404 | User Name: r | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
http [open] – Reg Error: Key error.
https [open] – "C:\Program Files\Mozilla Firefox\firefox.exe" -requestPending -osint -url "%1" (Mozilla Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0
"FirewallDisableNotify" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 4

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
"DoNotAllowExceptions" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"19459:TCP" = 19459:TCP:*:Enabled:BitComet 19459 TCP
"19459:UDP" = 19459:UDP:*:Enabled:BitComet 19459 UDP
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"1935:TCP" = 1935:TCP:*:Enabled:DramaFever 1935 TCP
"1935:UDP" = 1935:UDP:*:Enabled:DramaFever 1935 UDP

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"C:\Program Files\MSN Messenger\msnmsgr.exe" = C:\Program Files\MSN Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1 – File not found
"C:\Program Files\MSN Messenger\livecall.exe" = C:\Program Files\MSN Messenger\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone) – File not found

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\Java\jre6\bin\javaw.exe" = C:\Program Files\Java\jre6\bin\javaw.exe:*:Enabled:Java™ Platform SE binary – (Sun Microsystems, Inc.)


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{24BC8B57-716C-444F-B46B-A3349B9164C5}_is1" = Aegisub 2.1.6 Release Preview r2494
"{26A24AE4-039D-4CA4-87B4-2F83216013FF}" = Java™ 6 Update 21
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{3B6E3FC6-274C-4B6C-BC85-5C3B15DE18E2}" = Mega Manager
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{56C049BE-79E9-4502-BEA7-9754A3E60F9B}" = neroxml
"{6A6DCB18-3ECB-46DC-894B-5EFE08C0BD9B}" = Mega Manager
"{7748AC8C-18E3-43BB-959B-088FAEA16FB2}" = Nero StartSmart
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{86D4B82A-ABED-442A-BE86-96357B70F4FE}" = Ask Toolbar
"{90110409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Professional Edition 2003
"{91A4AD99-69CE-4745-97B7-0E0DFBECFDE5}" = Adobe Illustrator CS
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update
"{AC76BA86-7AD7-1033-7B44-A94000000001}" = Adobe Reader 9.4.0
"{B194272D-1F92-46DF-99EB-8D5CE91CB4EC}" = Adobe AIR
"{B2EC4A38-B545-4A00-8214-13FE0E915E6D}" = Advertising Center
"{BD5CA0DA-71AD-43DA-B19E-6EEE0C9ADC9A}" = Nero ControlCenter
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C81A2FE0-3574-00A9-CED4-BDAA334CBE8E}" = Nero Online Upgrade
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D103C4BA-F905-437A-8049-DB24763BBE36}" = Skype™ 4.2
"{D1FA9273-5698-3E48-D833-3DABC255837D}" = Saezuri
"{E8A80433-302B-4FF1-815D-FCC8EAC482FF}" = Nero Installer
"{e8d15c8e-f908-4b54-a425-6abdf0f547f1}" = Nero 9 Lite
"{EEED2879-F4AB-430A-998C-801D0E5B9C1E}" = KBS Kong v3
"{EFB21DE7-8C19-4A88-BB28-A766E16493BC}" = Adobe Photoshop CS
"{F0A37341-D692-11D4-A984-009027EC0A9C}" = SoundMAX
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}" = Visual C++ 2008 x86 Runtime - (v9.0.30729)
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}.vc_x86runtime_30729_01" = Visual C++ 2008 x86 Runtime - v9.0.30729.01
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player 11.5
"Audacity_is1" = Audacity 1.2.6
"AVG9Uninstall" = AVG Free 9.0
"AviSynth" = AviSynth 2.5
"CamStudio" = CamStudio
"CamStudio Lossless Codec_is1" = CamStudio Lossless Codec v1.4
"Dell Photo AIO Printer 962" = Dell Photo AIO Printer 962
"ERUNT_is1" = ERUNT 1.1j
"FoxyTunesForFirefox" = FoxyTunes for Firefox
"ie8" = Windows Internet Explorer 8
"Image Grabber II" = Image Grabber II
"jp.playwell.Saezuri.58F200D7EEA7AA1DF3962E867638EFEED92471BE.1" = Saezuri
"KLiteCodecPack_is1" = K-Lite Mega Codec Pack 5.0.5
"LastFM_is1" = Last.fm 1.5.4.24567
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Mozilla Firefox (3.6.11)" = Mozilla Firefox (3.6.11)
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"Picasa2" = Picasa 2
"RapidCRC" = RapidCRC 0.6.1
"SubtitleWorkshop" = Subtitle Workshop 2.51
"TVAnts 1.0" = TVAnts 1.0
"Veoh Web Player Beta" = Veoh Web Player
"VLC media player" = VideoLAN VLC media player 0.8.6b
"VobSub" = VobSub v2.23 (Remove Only)
"WinAVIVideoConverter_is1" = WinAVIVideoConverter
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 3
"WinRAR archiver" = WinRAR archiver
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"WMV9_VCM" = Microsoft Windows Media Video 9 VCM
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 5/12/2010 1:20:32 AM | Computer Name = R-EA6D203B44404 | Source = Application Hang | ID = 1002
Description = Hanging application mplayerc.exe, version 1.2.1008.0, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 5/15/2010 7:14:07 PM | Computer Name = R-EA6D203B44404 | Source = crypt32 | ID = 131083
Description = Failed extract of third-party root list from auto update cab at: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>
with error: The data is invalid.

Error - 5/17/2010 2:24:29 PM | Computer Name = R-EA6D203B44404 | Source = Application Error | ID = 1000
Description = Faulting application skype.exe, version 4.1.0.136, faulting module
skype.exe, version 4.1.0.136, fault address 0x000d7bc8.

Error - 5/17/2010 2:24:40 PM | Computer Name = R-EA6D203B44404 | Source = Application Error | ID = 1000
Description = Faulting application skype.exe, version 4.1.0.136, faulting module
skype.exe, version 4.1.0.136, fault address 0x000d7bc8.

Error - 5/18/2010 2:34:11 AM | Computer Name = R-EA6D203B44404 | Source = Application Hang | ID = 1002
Description = Hanging application IEXPLORE.EXE, version 6.0.2900.2180, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 7/2/2010 4:20:50 PM | Computer Name = R-EA6D203B44404 | Source = Application Error | ID = 1000
Description = Faulting application mplayerc.exe, version 1.2.1008.0, faulting module
quartz.dll, version 6.5.2600.3497, fault address 0x000b9f80.

Error - 7/13/2010 11:00:13 PM | Computer Name = R-EA6D203B44404 | Source = Userenv | ID = 1007
Description = Windows cannot determine the associated site for this computer. (The
RPC server is too busy to complete this operation. ). Group Policy processing aborted.


Error - 7/13/2010 11:01:12 PM | Computer Name = R-EA6D203B44404 | Source = Userenv | ID = 1007
Description = Windows cannot determine the associated site for this computer. (The
RPC server is too busy to complete this operation. ). Group Policy processing aborted.


Error - 7/18/2010 12:29:18 PM | Computer Name = R-EA6D203B44404 | Source = crypt32 | ID = 131083
Description = Failed extract of third-party root list from auto update cab at: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>
with error: A required certificate is not within its validity period when verifying
against the current system clock or the timestamp in the signed file.

Error - 7/18/2010 12:29:18 PM | Computer Name = R-EA6D203B44404 | Source = crypt32 | ID = 131083
Description = Failed extract of third-party root list from auto update cab at: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>
with error: A required certificate is not within its validity period when verifying
against the current system clock or the timestamp in the signed file.

[ System Events ]
Error - 10/19/2010 8:11:06 AM | Computer Name = R-EA6D203B44404 | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
Lbd

Error - 10/19/2010 11:09:32 PM | Computer Name = R-EA6D203B44404 | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
Lbd

Error - 10/20/2010 10:22:57 AM | Computer Name = R-EA6D203B44404 | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
Lbd

Error - 10/20/2010 12:29:43 PM | Computer Name = R-EA6D203B44404 | Source = Service Control Manager | ID = 7034
Description = The Java Quick Starter service terminated unexpectedly. It has done
this 1 time(s).

Error - 10/20/2010 2:08:50 PM | Computer Name = R-EA6D203B44404 | Source = Service Control Manager | ID = 7034
Description = The SoundMAX Agent Service service terminated unexpectedly. It has
done this 1 time(s).

Error - 10/20/2010 2:08:50 PM | Computer Name = R-EA6D203B44404 | Source = Service Control Manager | ID = 7031
Description = The AVG Free WatchDog service terminated unexpectedly. It has done
this 1 time(s). The following corrective action will be taken in 0 milliseconds:
Restart the service.

Error - 10/20/2010 2:08:50 PM | Computer Name = R-EA6D203B44404 | Source = Service Control Manager | ID = 7034
Description = The dlbx_device service terminated unexpectedly. It has done this
1 time(s).

Error - 10/20/2010 2:11:00 PM | Computer Name = R-EA6D203B44404 | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
Lbd

Error - 10/20/2010 2:36:58 PM | Computer Name = R-EA6D203B44404 | Source = SRService | ID = 104
Description = The System Restore initialization process failed.

Error - 10/20/2010 2:36:59 PM | Computer Name = R-EA6D203B44404 | Source = Service Control Manager | ID = 7023
Description = The System Restore Service service terminated with the following error:
%%2


< End of report >
Hi,

:welcome:

My name is NoodleTech. I would be glad to take a look at your log and help you with solving any malware problems. HijackThis logs can take a while to research, so please be patient and I'd be grateful if you would note the following:

  • I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.
As I'm still in training at What The Tech, all my posts needs to be checked by an expert first. This may cause a delay, but I will do my best to keep it as short as possible.
Hi fallenframes,

[external image: Posted Image]
  • Please download GMER from one of the following locations, and save it to your desktop:
  • Main Mirror
    This version will download a randomly named file (Recommended)
  • Zip Mirror
    This version will download a zip file you will need to extract first. If you use this mirror, please extract the zip file to your desktop.
  • Extract the contents of the zipped file to desktop (applicable only to Zip mirror) .
  • Double click [external image: Posted Image] or [external image: Posted Image] on your desktop.
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.
    [external image: Posted Image]

    [external image: Posted Image]
    Click the image to enlarge it
  • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and attach it in your reply.
**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries


Next, please download MBRCheck.exe to your desktop.
  • Be sure to disable your security programs
  • Double click on the file to run it (Vista and Windows 7 users will have to confirm the UAC prompt)
  • A window will open on your desktop
  • if an unknown bootcode is found you will have further options available to you, at this time press N then press Enter twice.
  • If nothing unusual is found just press Enter
  • A .txt file named MBRCheck_mm.dd.yy_hh.mm.ss should appear on your desktop.
  • Please post the contents of that file.
Hi. Here we go. 📎gmer.txt MBRCheck, version 1.2.3 © 2010, AD Command-line: Windows Version: Windows XP Professional Windows Information: Service Pack 3 (build 2600) Logical Drives Mask: 0x0000003d Kernel Drivers (total 122): 0x804D7000 \WINDOWS\system32\ntoskrnl.exe 0x806FF000 \WINDOWS\system32\hal.dll 0xF7AA3000 \WINDOWS\system32\KDCOM.DLL 0xF79B3000 \WINDOWS\system32\BOOTVID.dll 0xF7554000 ACPI.sys 0xF7AA5000 \WINDOWS\system32\DRIVERS\WMILIB.SYS 0xF7543000 pci.sys 0xF75A3000 isapnp.sys 0xF75B3000 ohci1394.sys 0xF75C3000 \WINDOWS\system32\DRIVERS\1394BUS.SYS 0xF7B6B000 PCIIde.sys 0xF7823000 \WINDOWS\System32\Drivers\PCIIDEX.SYS 0xF7AA7000 intelide.sys 0xF75D3000 MountMgr.sys 0xF7524000 ftdisk.sys 0xF7AA9000 dmload.sys 0xF74FE000 dmio.sys 0xF782B000 PartMgr.sys 0xF75E3000 VolSnap.sys 0xF74E6000 atapi.sys 0xF75F3000 disk.sys 0xF7603000 \WINDOWS\system32\DRIVERS\CLASSPNP.SYS 0xF74C6000 fltmgr.sys 0xF7613000 PxHelp20.sys 0xF74AF000 KSecDD.sys 0xF749C000 WudfPf.sys 0xF740F000 Ntfs.sys 0xF73E2000 NDIS.sys 0xF7623000 sbp2port.sys 0xF73C8000 Mup.sys 0xF7633000 agp440.sys 0xF7663000 \SystemRoot\system32\DRIVERS\nic1394.sys 0xF77E3000 \SystemRoot\system32\DRIVERS\intelppm.sys 0xF71B0000 \SystemRoot\system32\DRIVERS\nv4_mini.sys 0xF719C000 \SystemRoot\system32\DRIVERS\VIDEOPRT.SYS 0xF78CB000 \SystemRoot\system32\DRIVERS\usbuhci.sys 0xF7178000 \SystemRoot\system32\DRIVERS\USBPORT.SYS 0xF78D3000 \SystemRoot\system32\DRIVERS\usbehci.sys 0xF7154000 \SystemRoot\system32\DRIVERS\EL2K_XP.sys 0xF77F3000 \SystemRoot\system32\DRIVERS\i8042prt.sys 0xF78DB000 \SystemRoot\system32\DRIVERS\kbdclass.sys 0xF7803000 \SystemRoot\system32\DRIVERS\serial.sys 0xF7A6B000 \SystemRoot\system32\DRIVERS\serenum.sys 0xF78E3000 \SystemRoot\system32\DRIVERS\fdc.sys 0xF7140000 \SystemRoot\system32\DRIVERS\parport.sys 0xF7813000 \SystemRoot\system32\DRIVERS\cdrom.sys 0xF7673000 \SystemRoot\system32\DRIVERS\redbook.sys 0xF711D000 \SystemRoot\system32\DRIVERS\ks.sys 0xF7683000 \SystemRoot\system32\DRIVERS\imapi.sys 0xF708F000 \SystemRoot\system32\drivers\smwdm.sys 0xF706B000 \SystemRoot\system32\drivers\portcls.sys 0xF7693000 \SystemRoot\system32\drivers\drmk.sys 0xF7053000 \SystemRoot\system32\drivers\aeaudio.sys 0xF7C69000 \SystemRoot\system32\DRIVERS\audstub.sys 0xF76A3000 \SystemRoot\system32\DRIVERS\rasl2tp.sys 0xF7A77000 \SystemRoot\system32\DRIVERS\ndistapi.sys 0xF6F9C000 \SystemRoot\system32\DRIVERS\ndiswan.sys 0xF76B3000 \SystemRoot\system32\DRIVERS\raspppoe.sys 0xF76C3000 \SystemRoot\system32\DRIVERS\raspptp.sys 0xF78EB000 \SystemRoot\system32\DRIVERS\TDI.SYS 0xF6F8B000 \SystemRoot\system32\DRIVERS\psched.sys 0xF76D3000 \SystemRoot\system32\DRIVERS\msgpc.sys 0xF78F3000 \SystemRoot\system32\DRIVERS\ptilink.sys 0xF78FB000 \SystemRoot\system32\DRIVERS\raspti.sys 0xF6F33000 \SystemRoot\system32\DRIVERS\rdpdr.sys 0xF76E3000 \SystemRoot\system32\DRIVERS\termdd.sys 0xF7903000 \SystemRoot\system32\DRIVERS\mouclass.sys 0xF7ABF000 \SystemRoot\system32\DRIVERS\swenum.sys 0xF6ED5000 \SystemRoot\system32\DRIVERS\update.sys 0xF7A93000 \SystemRoot\system32\DRIVERS\mssmbios.sys 0xF7703000 \SystemRoot\System32\Drivers\NDProxy.SYS 0xF7713000 \SystemRoot\system32\DRIVERS\usbhub.sys 0xF7AC5000 \SystemRoot\system32\DRIVERS\USBD.SYS 0xF790B000 \SystemRoot\system32\DRIVERS\flpydisk.sys 0xF7AC7000 \SystemRoot\System32\Drivers\Fs_Rec.SYS 0xF7CD2000 \SystemRoot\System32\Drivers\Null.SYS 0xF7AC9000 \SystemRoot\System32\Drivers\Beep.SYS 0xF791B000 \SystemRoot\System32\drivers\vga.sys 0xF7ACB000 \SystemRoot\System32\Drivers\mnmdd.SYS 0xF7ACD000 \SystemRoot\System32\DRIVERS\RDPCDD.sys 0xF7923000 \SystemRoot\System32\Drivers\Msfs.SYS 0xF792B000 \SystemRoot\System32\Drivers\Npfs.SYS 0xF7A3F000 \SystemRoot\system32\DRIVERS\rasacd.sys 0xF5D21000 \SystemRoot\system32\DRIVERS\ipsec.sys 0xF5CC8000 \SystemRoot\system32\DRIVERS\tcpip.sys 0xF5C7A000 \SystemRoot\system32\DRIVERS\ipnat.sys 0xF5C40000 \SystemRoot\System32\Drivers\avgtdix.sys 0xF7753000 \SystemRoot\system32\DRIVERS\wanarp.sys 0xF7763000 \SystemRoot\system32\DRIVERS\arp1394.sys 0xF7A5F000 \SystemRoot\system32\DRIVERS\hidusb.sys 0xF7773000 \SystemRoot\system32\DRIVERS\HIDCLASS.SYS 0xF793B000 \SystemRoot\system32\DRIVERS\HIDPARSE.SYS 0xF5B78000 \SystemRoot\system32\DRIVERS\netbt.sys 0xF5B56000 \SystemRoot\System32\drivers\afd.sys 0xF7783000 \SystemRoot\system32\DRIVERS\netbios.sys 0xF5B2B000 \SystemRoot\system32\DRIVERS\rdbss.sys 0xF5ABB000 \SystemRoot\system32\DRIVERS\mrxsmb.sys 0xF7793000 \SystemRoot\System32\Drivers\Fips.SYS 0xF7943000 \SystemRoot\System32\Drivers\avgmfx86.sys 0xF5A87000 \SystemRoot\System32\Drivers\avgldx86.sys 0xF6F7F000 \SystemRoot\system32\DRIVERS\mouhid.sys 0xF6FC3000 \SystemRoot\System32\Drivers\Cdfs.SYS 0xF5A47000 \SystemRoot\System32\Drivers\dump_atapi.sys 0xF7B27000 \SystemRoot\System32\Drivers\dump_WMILIB.SYS 0xBF800000 \SystemRoot\System32\win32k.sys 0xF6F73000 \SystemRoot\System32\drivers\Dxapi.sys 0xF79AB000 \SystemRoot\System32\watchdog.sys 0xBF000000 \SystemRoot\System32\drivers\dxg.sys 0xF7CB7000 \SystemRoot\System32\drivers\dxgthk.sys 0xBF012000 \SystemRoot\System32\nv4_disp.dll 0xBFFA0000 \SystemRoot\System32\ATMFD.DLL 0xF3D23000 \SystemRoot\system32\DRIVERS\ndisuio.sys 0xF392E000 \SystemRoot\system32\DRIVERS\mrxdav.sys 0xF7ABD000 \SystemRoot\System32\Drivers\ParVdm.SYS 0xF38A1000 \SystemRoot\system32\drivers\wdmaud.sys 0xF3B2B000 \SystemRoot\system32\drivers\sysaudio.sys 0xF384A000 \SystemRoot\system32\DRIVERS\srv.sys 0xF36DD000 \SystemRoot\system32\drivers\kmixer.sys 0xF3279000 \SystemRoot\System32\Drivers\Fastfat.SYS 0xF31E8000 \SystemRoot\System32\Drivers\HTTP.sys 0xF2661000 \??\C:\DOCUME~1\r\LOCALS~1\Temp\fwliapod.sys 0x7C900000 \WINDOWS\system32\ntdll.dll Processes (total 37): 0 System Idle Process 4 System 716 C:\WINDOWS\system32\smss.exe 764 csrss.exe 788 C:\WINDOWS\system32\winlogon.exe 836 C:\WINDOWS\system32\services.exe 848 C:\WINDOWS\system32\lsass.exe 1016 C:\WINDOWS\system32\svchost.exe 1084 svchost.exe 1180 C:\WINDOWS\system32\svchost.exe 1220 C:\WINDOWS\system32\svchost.exe 1276 svchost.exe 1380 svchost.exe 1516 C:\Program Files\AVG\AVG9\avgchsvx.exe 1524 C:\Program Files\AVG\AVG9\avgrsx.exe 1628 C:\Program Files\AVG\AVG9\avgcsrvx.exe 1656 C:\WINDOWS\system32\spoolsv.exe 1936 svchost.exe 2036 C:\Program Files\AVG\AVG9\avgwdsvc.exe 280 C:\Program Files\Java\jre6\bin\jqs.exe 308 C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE 436 C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe 532 C:\WINDOWS\system32\svchost.exe 1324 C:\WINDOWS\explorer.exe 1724 C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe 1964 C:\Program Files\Dell Photo AIO Printer 962\dlbxmon.exE 1512 C:\PROGRA~1\AVG\AVG9\avgtray.exe 2056 C:\Program Files\Analog Devices\SoundMAX\SMax4.exe 2064 C:\Program Files\Common Files\Java\Java Update\jusched.exe 2112 C:\WINDOWS\system32\ctfmon.exe 2492 C:\Program Files\AVG\AVG9\avgnsx.exe 3004 alg.exe 3064 C:\WINDOWS\system32\dlbxcoms.exe 3508 C:\Program Files\Mozilla Firefox\firefox.exe 3936 C:\WINDOWS\system32\wuauclt.exe 1976 C:\WINDOWS\system32\wscntfy.exe 3652 C:\Documents and Settings\r\Desktop\MBRCheck.exe \\.\C: –> \\.\PhysicalDrive0 at offset 0x00000000`00007e00 (NTFS) \\.\D: –> \\.\PhysicalDrive0 at offset 0x00000007`52c65e00 (NTFS) PhysicalDrive0 Model Number: WDCWD1200JD-22GBB0, Rev: 02.05D02 Size Device Name MBR Status ——————————————– 111 GB \\.\PhysicalDrive0 Windows XP MBR code detected SHA1: 31D100779DE502702C374F7C15687B56FCFD5528 Done!
Thanks for the logs fallenframes!

Let's try this.

Download ComboFix from one of the following locations:
Link 1
Link 2

VERY IMPORTANT !!! Save ComboFix.exe to your Desktop

* IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
  • Double click on ComboFix.exe & follow the prompts.
As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]

  • Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]

  • Click on Yes, to continue scanning for malware.
When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.
Notes:
1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.
Sorry I've been busy with work and haven't had time to do the Combofix scan just yet. I'll try to get it done, at the latest, Saturday.
Sorry for the delay.
Here's the Combofix

ComboFix 10-10-30.01 - r 10/30/2010 19:06:56.3.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1023.549 [GMT -4:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.

((((((((((((((((((((((((( Files Created from 2010-09-28 to 2010-10-30 )))))))))))))))))))))))))))))))
.

2010-10-20 17:57 . 2010-10-20 18:10 ——– d—–w- c:\program files\LG Electronics
2010-10-16 17:50 . 2010-10-16 17:50 ——– d—–w- c:\program files\Saezuri

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
.

——- Sigcheck ——-

[-] 2006-10-19 01:47 . C51B4A5C05A5475708E3C81C7765B71D . 27136 . . [11.0.5721.5145] . . c:\windows\system32\mspmsnsv.dll
[-] 2006-10-19 01:47 . C51B4A5C05A5475708E3C81C7765B71D . 27136 . . [11.0.5721.5145] . . c:\windows\system32\dllcache\mspmsnsv.dll
[-] 2004-08-11 06:45 . A477391B7A8B0A0DAABADB17CF533A4B . 25088 . . [10.0.3790.3646] . . c:\windows\$NtUninstallWMFDist11$\mspmsnsv.dll
[-] 2004-08-11 06:45 . A477391B7A8B0A0DAABADB17CF533A4B . 25088 . . [10.0.3790.3646] . . c:\windows\RegisteredPackages\{30C7234B-6482-4A55-A11D-ECD9030313F2}\MsPMSNSv.dll
[-] 2004-08-04 12:00 . C086483E3DBA8C1C0A687EC8D5B3D4C1 . 52224 . . [9.0.1.56] . . c:\windows\RegisteredPackages\{30C7234B-6482-4A55-A11D-ECD9030313F2}$BACKUP$\System\MsPMSNSv.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
2010-06-10 21:28 1233288 —-a-w- c:\program files\Ask.com\GenericAskToolbar.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2010-06-10 1233288]

[HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2010-06-10 1233288]

[HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2004-08-04 208952]
"PHIME2002ASync"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-04 455168]
"PHIME2002A"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-04 455168]
"SoundMAXPnP"="c:\program files\Analog Devices\SoundMAX\SMax4PNP.exe" [2003-05-29 790528]
"DLBXCATS"="c:\windows\System32\spool\DRIVERS\W32X86\3\DLBXtime.dll" [2004-12-07 69632]
"dlbxmon.exe"="c:\program files\Dell Photo AIO Printer 962\dlbxmon.exe" [2005-01-18 425984]
"AVG9_TRAY"="c:\progra~1\AVG\AVG9\avgtray.exe" [2010-10-04 2067808]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-05-14 248552]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-09-23 35760]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-09-21 932288]

c:\documents and settings\r\Start Menu\Programs\Startup\
ERUNT AutoBackup.lnk - c:\program files\ERUNT\AUTOBACK.EXE [2005-10-20 38912]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2007-6-12 110592]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2010-07-16 14:22 12536 —-a-w- c:\windows\system32\avgrsstx.dll

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\Java\\jre6\\bin\\javaw.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"19459:TCP"= 19459:TCP:BitComet 19459 TCP
"19459:UDP"= 19459:UDP:BitComet 19459 UDP
"1935:TCP"= 1935:TCP:DramaFever 1935 TCP
"1935:UDP"= 1935:UDP:DramaFever 1935 UDP

R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [3/30/2009 5:17 PM 216400]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [3/30/2009 5:17 PM 243024]
R2 avg9wd;AVG Free WatchDog;c:\program files\AVG\AVG9\avgwdsvc.exe [7/16/2010 10:22 AM 308136]
S0 Lbd;Lbd;c:\windows\system32\DRIVERS\Lbd.sys –> c:\windows\system32\DRIVERS\Lbd.sys [?]
S3 scsk5;SCSK5 Driver Service;c:\windows\system32\drivers\scsk5.sys –> c:\windows\system32\drivers\scsk5.sys [?]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
getPlusHelper REG_MULTI_SZ getPlusHelper
.
Contents of the 'Scheduled Tasks' folder

2010-10-27 c:\windows\Tasks\Scheduled Update for Ask Toolbar.job
- c:\program files\Ask.com\UpdateTask.exe [2010-06-10 21:28]
.
.
——- Supplementary Scan ——-
.
uStart Page = about:blank
uInternet Connection Wizard,ShellNext = iexplore
IE: Download Link Using Mega Manager… - c:\program files\Megaupload\Mega Manager\mm_file.htm
IE: E&xport; to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
DPF: {0349EF81-B9C1-4B97-86F7-7B931D0E2532} - hxxp://sticube.clubbox.co.kr/sticubeupdate/cab/NowStarter2.cab
DPF: {049A470D-F818-4E34-B14D-E4E237DADCF8} - hxxp://www.shockwave.com/content/fashiondash/sis/fashiondashweb.1.0.0.21.cab
FF - ProfilePath - c:\documents and settings\r\Application Data\Mozilla\Firefox\Profiles\ltwnytn6.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://mail.google.com/
FF - prefs.js: keyword.URL - hxxp://ca.search.yahoo.com/search?ei=utf-8&fr;=megaup&p;=
FF - component: c:\documents and settings\r\Application Data\Mozilla\Firefox\Profiles\ltwnytn6.default\extensions\{463F6CA5-EE3C-4be1-B7E6-7FEE11953374}\platform\WINNT\components\FoxyTunes.dll
FF - component: c:\program files\AVG\AVG9\Firefox\components\avgssff.dll
FF - plugin: c:\program files\Java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\K-Lite Codec Pack\Real\browser\plugins\nppl3260.dll
FF - plugin: c:\program files\K-Lite Codec Pack\Real\browser\plugins\nprpjplug.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npmozax.dll
FF - plugin: c:\program files\Veoh Networks\VeohWebPlayer\NPVeohTVPlugin.dll
FF - plugin: c:\program files\Veoh Networks\VeohWebPlayer\npWebPlayerVideoPluginATL.dll

—- FIREFOX POLICIES —-
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgbaam7a8h", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–fiqz9s", true); // Traditional
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–fiqs8s", true); // Simplified
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–j6w193g", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgberp4a5d4ar", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgberp4a5d4a87g", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgbqly7c0a67fbc", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgbqly7cvafr", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–kpry57d", true); // Traditional
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–kprw13d", true); // Simplified
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-10-30 19:11
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
DLBXCATS = rundll32 c:\windows\System32\spool\DRIVERS\W32X86\3\DLBXtime.dll,_RunDLLEntry@16???????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'explorer.exe'(2228)
c:\windows\system32\WININET.dll
c:\progra~1\WINDOW~2\wmpband.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
Completion time: 2010-10-30 19:13:14
ComboFix-quarantined-files.txt 2010-10-30 23:13

Pre-Run: 12,175,798,272 bytes free
Post-Run: 12,221,927,424 bytes free

- - End Of File - - 40A144A04EDF6D7D72AF6531AB9FBCD4
Hello fallenframes, thanks for the log. It looks like you have run ComboFix before. I would like to take a look at the logs from the previous runs. Please browse to C:\Qoobox and post the contents of each combofix.txt file.

Next,

Copy/paste the text in the Codebox below into notepad:

Here's how to do that:
Click Start > Run type Notepad click OK.
This will open an empty notepad file:

Take your mouse, and place your cursor at the beginning of the text in the box below, then click and hold the left mouse button, while pulling your mouse over the text. This should highlight the text. Now release the left mouse button. Now, with the cursor over the highlighted text, right click the mouse for options, and select 'copy'. Now over the empty Notepad box, right click your mouse again, and select 'paste' and you will have copied and pasted the text.

File::
c:\windows\system32\drivers\scsk5.sys

Driver::
scsk5
Save this file to your desktop, Save this as "CFScript"

Here's how to do that:
1.Click File;
2.Click Save As… Change the directory to your desktop;
3.Change the Save as type to "All Files";
4.Type in the file name: CFScript
5.Click Save …


[external image: Posted Image]

Drag CFScript.txt into ComboFix.exe


Then post the results log using Copy / Paste
it could have been when i used it back in july. there are no combofix.txt logs in qoobox now. i dragged cfscript over combofix and it was starting and then my avg scan started. i cancelled it… and then combofix told me there was a new update, which i agreed to update and it restarted on me. re-did the drag cfscript to combofix, but now it's telling me combofix cannot run because it is installed and i should uninstall it. avg was disabled since saturday when i did the combofix scan, but did the scheduled avg scan that started have anything to do with combofix detecting that avg is installed and saying it's dangerous to run even though i have it disabled? have these logs been helping? should i uninstall avg now so i can do the cfscript step? i'm sorry this is taking a while. lately, i haven't had time to use or been too tired to turn on this computer, so i've only come on to reply in this thread. was avg's detection a false alarm or did avg actually already remove it? i guess we will know when you and i are finally done here.
Hi fallenframes,

No problem.

Combofix has been updated and will not run unless AVG is completely uninstalled.

We need to uninstall AVG before we can run the CFScript. We can install a different antivirus software after we finish cleaning the computer.
Please click here to download the AVG removal tool. Run the tool and follow the prompts to uninstall AVG.

Then repeat the CFScript steps to run the CFScript.

Please post the combofix log after running the script.
Hi, uninstalled AVG using the tool you provided. I then did the cfscript step again and it updated combofix again and restarted. I left, came back and the computer was restarting. I was watching it and it came to the screen, showing combofix, but then automatically restarted again. 2nd time around, it showed the pop up saying Windows had a serious error. The combofix scan got interrupted? :/ cfscript file disappeared from the desktop and after looking at c:\qoobox, it seems to have been moved there. CFScript_used_2010-11-04_13.10.31 what to do now? >.<
Hi fallenframes, Did you reboot the machine? This isn't unexpected when certain infections are present. ComboFix should have continued after a reboot and created a log, check at C:\ComboFix.txt and post the log if located there, If no log, please re-run ComboFix, make sure your security programs are disabled, or they will interfere.
yes, it did reboot and the scan was continuing to produce the log, but for some reason it rebooted again. okay, there's no C:\ComboFix.txt, but there is a ComboFix folder now with 267 objects. Found this though: ComboFix 10-11-03.04 - r 11/04/2010 13:10:33.4.2 - x86 Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1023.656 [GMT -4:00] Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe Command switches used :: C:\Documents and Settings\r\Desktop\CFScript.txt AV: AVG Anti-Virus Free *On-access scanning disabled* (Outdated) {17DDD097-36FF-435F-9E1B-52D74245D6BF} FILE :: "c:\windows\system32\drivers\scsk5.sys" . So for the re-run, do I re-run Combofix with the CFScript step or without?

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI