This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Computer Suspected hijacking

21 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hey, My computer is running really slow upon opening programmes such as browsers and other documents ect. I also get my mouse going haywire opening up other programs and messing around with them?? I did a scan on Avast and it notified me with a virus which i deleted?? Can you help me fix this problem?? Cheers
Hi,

:welcome:

My name is NoodleTech. I would be glad to take a look at your log and help you with solving any malware problems. HijackThis logs can take a while to research, so please be patient and I'd be grateful if you would note the following:

  • I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.
As I'm still in training at What The Tech, all my posts needs to be checked by an expert first. This may cause a delay, but I will do my best to keep it as short as possible.
  • Download OTL to your desktop.
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Check the boxes beside LOP Check and Purity Check.
  • Under Custom Scan paste this in

    netsvcs
    drivers32
    %SYSTEMDRIVE%\*.*
    %systemroot%\Fonts\*.com
    %systemroot%\Fonts\*.dll
    %systemroot%\Fonts\*.ini
    %systemroot%\Fonts\*.ini2
    %systemroot%\Fonts\*.exe
    %systemroot%\system32\spool\prtprocs\w32x86\*.*
    %systemroot%\REPAIR\*.bak1
    %systemroot%\REPAIR\*.ini
    %systemroot%\system32\*.jpg
    %systemroot%\*.jpg
    %systemroot%\*.png
    %systemroot%\*.scr
    %systemroot%\*._sy
    %APPDATA%\Adobe\Update\*.*
    %ALLUSERSPROFILE%\Favorites\*.*
    %APPDATA%\Microsoft\*.*
    %PROGRAMFILES%\*.*
    %APPDATA%\Update\*.*
    %systemroot%\*. /mp /s
    CREATERESTOREPOINT
    %systemroot%\System32\config\*.sav
    %PROGRAMFILES%\bak. /s
    %systemroot%\system32\bak. /s
    %ALLUSERSPROFILE%\Start Menu\*.lnk /x
    %systemroot%\system32\config\systemprofile\*.dat /x
    %systemroot%\*.config
    %systemroot%\system32\*.db
    %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x
    %USERPROFILE%\Desktop\*.exe
    %PROGRAMFILES%\Common Files\*.*
    %systemroot%\*.src
    %systemroot%\install\*.*
    %systemroot%\system32\DLL\*.*
    %systemroot%\system32\HelpFiles\*.*
    %systemroot%\system32\rundll\*.*
    %systemroot%\winn32\*.*
    %systemroot%\Java\*.*
    %systemroot%\system32\test\*.*
    %systemroot%\system32\Rundll32\*.*
    %systemroot%\AppPatch\Custom\*.*
    %APPDATA%\Roaming\Microsoft\Windows\Recent\*.lnk /x
    %PROGRAMFILES%\PC-Doctor\Downloads\*.*
    %PROGRAMFILES%\Internet Explorer\*.tmp
    %PROGRAMFILES%\Internet Explorer\*.dat
    %USERPROFILE%\My Documents\*.exe
    %USERPROFILE%\*.exe
    %systemroot%\ADDINS\*.*
    %systemroot%\assembly\*.bak2
    %systemroot%\Config\*.*
    %systemroot%\REPAIR\*.bak2
    %systemroot%\SECURITY\Database\*.sdb /x
    %systemroot%\SYSTEM\*.bak2
    %systemroot%\Web\*.bak2
    %systemroot%\Driver Cache\*.*
    %PROGRAMFILES%\Mozilla Firefox\0*.exe
    %ProgramFiles%\Microsoft Common\*.*
    %ProgramFiles%\TinyProxy.
    %USERPROFILE%\Favorites\*.url /x
    %systemroot%\system32\*.bk
    %systemroot%\*.te
    %systemroot%\system32\system32\*.*
    %ALLUSERSPROFILE%\*.dat /x
    %systemroot%\system32\drivers\*.rmv
    dir /b "%systemroot%\system32\*.exe" | find /i " " /c
    dir /b "%systemroot%\*.exe" | find /i " " /c
    %PROGRAMFILES%\Microsoft\*.*
    %systemroot%\System32\Wbem\proquota.exe
    %PROGRAMFILES%\Mozilla Firefox\*.dat
    %USERPROFILE%\Cookies\*.txt /x
    %SystemRoot%\system32\fonts\*.*
    HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs

  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply.
  • You may need two posts to fit them both in.
TL logfile created on: 12/12/2010 2:39:11 PM - Run 1
OTL by OldTimer - Version 3.2.17.3 Folder = C:\Documents and Settings\Hills\My Documents\Downloads
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000C09 | Country: Australia | Language: ENA | Date Format: d/MM/yyyy

224.00 Mb Total Physical Memory | 117.00 Mb Available Physical Memory | 52.00% Memory free
931.00 Mb Paging File | 768.00 Mb Available in Paging File | 82.00% Paging File free
Paging file location(s): C:\pagefile.sys 720 1440 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 37.26 Gb Total Space | 7.18 Gb Free Space | 19.26% Space Free | Partition Type: NTFS

Computer Name: YEOLDINN | User Name: Hills | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\Hills\My Documents\Downloads\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Alwil Software\Avast5\AvastUI.exe (AVAST Software)
PRC - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe (AVAST Software)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\NETGEAR\WG111v2\WG111v2.exe ()


========== Modules (SafeList) ==========

MOD - C:\Documents and Settings\Hills\My Documents\Downloads\OTL.exe (OldTimer Tools)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV - (HidServ) – C:\WINDOWS\System32\hidserv.dll File not found
SRV - (nosGetPlusHelper) getPlus® – C:\Program Files\NOS\bin\getPlus_Helper_3004.dll (NOS Microsystems Ltd.)
SRV - (avast! Web Scanner) – C:\Program Files\Alwil Software\Avast5\AvastSvc.exe (AVAST Software)
SRV - (avast! Mail Scanner) – C:\Program Files\Alwil Software\Avast5\AvastSvc.exe (AVAST Software)
SRV - (avast! Antivirus) – C:\Program Files\Alwil Software\Avast5\AvastSvc.exe (AVAST Software)
SRV - (aspnet_state) – C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\aspnet_state.exe (Microsoft Corporation)
SRV - (WPFFontCache_v0400) – C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe (Microsoft Corporation)
SRV - (clr_optimization_v4.0.30319_32) – C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (NetTcpPortSharing) – C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe (Microsoft Corporation)
SRV - (Nero BackItUp Scheduler 4.0) – C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe (Nero AG)


========== Driver Services (SafeList) ==========

DRV - (ncnvyc) – C:\WINDOWS\System32\drivers\pqnersy.sys File not found
DRV - (catchme) – C:\DOCUME~1\Hills\LOCALS~1\Temp\catchme.sys File not found
DRV - (aswTdi) – C:\WINDOWS\System32\drivers\aswTdi.sys (AVAST Software)
DRV - (aswSP) – C:\WINDOWS\System32\drivers\aswSP.sys (AVAST Software)
DRV - (aswRdr) – C:\WINDOWS\System32\drivers\aswRdr.sys (AVAST Software)
DRV - (aswMon2) – C:\WINDOWS\System32\drivers\aswmon2.sys (AVAST Software)
DRV - (aswFsBlk) – C:\WINDOWS\System32\drivers\aswFsBlk.sys (AVAST Software)
DRV - (Aavmker4) – C:\WINDOWS\System32\drivers\aavmker4.sys (AVAST Software)
DRV - (USB_RNDIS) – C:\WINDOWS\system32\drivers\usb8023.sys (Microsoft Corporation)
DRV - (gameenum) – C:\WINDOWS\system32\drivers\gameenum.sys (Microsoft Corporation)
DRV - (RTLWUSB) – C:\WINDOWS\system32\drivers\wg111v2.sys (NETGEAR Inc.)
DRV - (AN983) – C:\WINDOWS\system32\drivers\an983.sys (ADMtek Incorporated.)
DRV - (alcaudsl) – C:\WINDOWS\system32\drivers\alcaudsl.sys (THOMSON)
DRV - (alcan5ln) SpeedTouch™ USB ADSL RFC1483 Networking Driver (NDIS) – C:\WINDOWS\system32\drivers\alcan5ln.sys (THOMSON)
DRV - (sisagp) – C:\WINDOWS\system32\DRIVERS\SISAGPX.sys (Silicon Integrated Systems Corporation)
DRV - (SiS7012) Service for AC'97 Sample Driver (WDM) – C:\WINDOWS\system32\drivers\sis7012.sys (Silicon Integrated Systems Corporation)
DRV - (SiS315) – C:\WINDOWS\system32\drivers\sisgrp.sys (Silicon Integrated Systems Corporation)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========


IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://au.yahoo.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-au
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 7E B5 1F 17 DF 2A CB 01 [binary data]
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.search.defaultenginename: "Yahoo! Search"
FF - prefs.js..browser.search.selectedEngine: "Yahoo! Search"
FF - prefs.js..browser.startup.homepage: "Http://ninemsn.com.au"
FF - prefs.js..extensions.enabledItems: {AA052FD6-366A-4771-A591-0D8DC551585D}:1.1.20
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: {a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7}:20100908
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems: {ACAA314B-EEBA-48e4-AD47-84E31C44796C}:1.0.1
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21
FF - prefs.js..extensions.enabledItems: {872b5b88-9db5-4310-bdd0-ac189557e5f5}:2.7.2.0
FF - prefs.js..network.proxy.http_port: 3


FF - HKLM\software\mozilla\Mozilla Firefox 3.6.12\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/11/18 15:23:35 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.12\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/11/20 11:27:39 | 000,000,000 | —D | M]

[2009/10/07 01:37:43 | 000,000,000 | —D | M] – C:\Documents and Settings\Hills\Application Data\Mozilla\Extensions
[2009/10/07 01:37:43 | 000,000,000 | —D | M] – C:\Documents and Settings\Hills\Application Data\Mozilla\Extensions\[removed]
[2010/12/12 13:17:09 | 000,000,000 | —D | M] – C:\Documents and Settings\Hills\Application Data\Mozilla\Firefox\Profiles\c5apz7ds.default\extensions
[2010/04/30 17:16:40 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Documents and Settings\Hills\Application Data\Mozilla\Firefox\Profiles\c5apz7ds.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010/10/26 12:08:57 | 000,000,000 | —D | M] (DVDVideoSoftTB Toolbar) – C:\Documents and Settings\Hills\Application Data\Mozilla\Firefox\Profiles\c5apz7ds.default\extensions\{872b5b88-9db5-4310-bdd0-ac189557e5f5}
[2010/09/19 18:09:41 | 000,000,000 | —D | M] (WOT) – C:\Documents and Settings\Hills\Application Data\Mozilla\Firefox\Profiles\c5apz7ds.default\extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7}
[2010/11/02 16:55:38 | 000,000,000 | —D | M] (Calculator) – C:\Documents and Settings\Hills\Application Data\Mozilla\Firefox\Profiles\c5apz7ds.default\extensions\{AA052FD6-366A-4771-A591-0D8DC551585D}
[2010/07/24 16:37:08 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Hills\Application Data\Mozilla\Firefox\Profiles\c5apz7ds.default\extensions\{ACAA314B-EEBA-48e4-AD47-84E31C44796C}
[2010/12/12 13:17:09 | 000,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions
[2010/05/07 12:29:16 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
[2010/08/24 18:41:53 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
[2010/08/24 18:41:26 | 000,423,656 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll

O1 HOSTS File: ([2010/08/27 14:24:26 | 000,000,027 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O4 - HKLM..\Run: [avast5] C:\Program Files\Alwil Software\Avast5\avastUI.exe (AVAST Software)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\NETGEAR WG111v2 Smart Wizard.lnk = C:\Program Files\NETGEAR\WG111v2\WG111v2.exe ()
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\control panel present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Infodelivery present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LinkResolveIgnoreLinkInfo = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveSearch = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\control panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LinkResolveIgnoreLinkInfo = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: Free YouTube to Mp3 Converter - C:\Documents and Settings\Hills\Application Data\DVDVideoSoftIEHelpers\youtubetomp3.htm ()
O9 - Extra Button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : &Blog; This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://update.microsoft.com/microsoftupdat…b?1248238891750 (MUWebControl Class)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos/OnlineScanner.cab (Reg Error: Value error.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload.macromedia.com/pub/shock…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (get_atlcom Class)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed] [removed]
O18 - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Program Files\Windows Live\Mail\mailcomm.dll (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\Hills\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Hills\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/07/21 09:34:02 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O34 - HKLM BootExecute: (aswBoot.exe /A:"C:" /A:"*" /L:"1033" /heur:80 /pup /archives /IA:0 /KBD:2 /dir:"C:\Program Files\Alwil Software\Avast5") - C:\WINDOWS\System32\aswBoot.exe (AVAST Software)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: 6to4 - File not found
NetSvcs: HidServ - C:\WINDOWS\System32\hidserv.dll File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found

Drivers32: msacm.ac3filter - C:\WINDOWS\System32\ac3filter.acm ()
Drivers32: msacm.divxa32 - C:\WINDOWS\System32\msaud32_divx.acm (Microsoft Corporation)
Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.lameacm - C:\WINDOWS\System32\lameACM.acm (http://www.mp3dev.org/)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.divx - C:\WINDOWS\System32\DivX.dll (DivX, Inc.)
Drivers32: vidc.ffds - C:\WINDOWS\System32\ff_vfw.dll ()
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)
Drivers32: vidc.vp60 - C:\WINDOWS\System32\vp6vfw.dll (On2.com)
Drivers32: vidc.vp61 - C:\WINDOWS\System32\vp6vfw.dll (On2.com)
Drivers32: vidc.vp62 - C:\WINDOWS\System32\vp6vfw.dll (On2.com)
Drivers32: vidc.XVID - C:\WINDOWS\System32\xvidvfw.dll ()
Drivers32: vidc.yv12 - C:\WINDOWS\System32\DivX.dll (DivX, Inc.)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point (16902109354000384)

========== Files/Folders - Created Within 30 Days ==========

[2010/12/12 12:48:16 | 000,000,000 | RH-D | C] – C:\Documents and Settings\Hills\Recent
[2010/12/11 15:40:58 | 000,272,128 | —- | C] (NETGEAR Inc.) – C:\WINDOWS\System32\drivers\wg111v2.sys
[2010/12/11 15:40:56 | 000,143,360 | —- | C] (TODO: ) – C:\WINDOWS\System32\IpLib.dll
[2010/12/11 15:40:51 | 000,000,000 | -H-D | C] – C:\Program Files\InstallShield Installation Information
[2010/12/11 15:40:51 | 000,000,000 | —D | C] – C:\Program Files\NETGEAR
[2010/12/11 15:40:37 | 000,000,000 | —D | C] – C:\Documents and Settings\Hills\Application Data\InstallShield
[2010/12/11 12:33:42 | 000,266,240 | —- | C] (WG111v2) – C:\WINDOWS\System32\WG1v2lib.dll
[2010/12/11 12:33:41 | 001,069,056 | —- | C] (The OpenSSL Project, http://www.openssl.org/) – C:\WINDOWS\System32\libeay32.dll
[2010/12/08 17:21:48 | 000,000,000 | —D | C] – C:\Program Files\Conduit
[2010/12/07 16:04:20 | 000,000,000 | —D | C] – C:\Program Files\NOS
[2010/12/07 16:04:20 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\NOS
[2010/12/05 11:26:19 | 000,005,632 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\write.exe
[2010/12/05 11:26:19 | 000,005,632 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\write.exe
[2010/12/05 11:26:12 | 000,138,752 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\sndvol32.exe
[2010/12/05 11:26:12 | 000,138,752 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\sndvol32.exe
[2010/12/05 11:26:11 | 000,073,216 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\avwav.dll
[2010/12/05 11:26:11 | 000,073,216 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\avwav.dll
[2010/12/05 11:26:11 | 000,044,544 | —- | C] (Hilgraeve, Inc.) – C:\WINDOWS\System32\hticons.dll
[2010/12/05 11:26:11 | 000,016,384 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\avmeter.dll
[2010/12/05 11:26:11 | 000,016,384 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\avmeter.dll
[2010/12/05 11:26:10 | 000,227,840 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\avtapi.dll
[2010/12/05 11:26:10 | 000,227,840 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\avtapi.dll
[2010/12/05 11:26:10 | 000,035,328 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\winchat.exe
[2010/12/05 11:26:10 | 000,035,328 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\winchat.exe
[2010/12/05 11:26:04 | 000,605,696 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\getuname.dll
[2010/12/05 11:26:04 | 000,605,696 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\getuname.dll
[2010/12/05 11:26:04 | 000,080,384 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\charmap.exe
[2010/12/05 11:26:04 | 000,080,384 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\charmap.exe
[2010/12/05 11:26:03 | 000,126,976 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\mshearts.exe
[2010/12/05 11:26:03 | 000,126,976 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\mshearts.exe
[2010/12/05 11:26:03 | 000,119,808 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\winmine.exe
[2010/12/05 11:26:03 | 000,119,808 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\winmine.exe
[2010/12/05 11:26:03 | 000,114,688 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\calc.exe
[2010/12/05 11:26:03 | 000,114,688 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\calc.exe
[2010/12/05 11:26:03 | 000,056,832 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\sol.exe
[2010/12/05 11:26:03 | 000,056,832 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\sol.exe
[2010/12/05 11:26:02 | 000,055,296 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\freecell.exe
[2010/12/05 11:26:02 | 000,055,296 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\freecell.exe
[2010/11/26 20:05:16 | 000,000,000 | -HSD | C] – C:\RECYCLER
[2010/11/21 22:52:58 | 000,000,000 | —D | C] – C:\Documents and Settings\Hills\Application Data\Malwarebytes
[2010/11/21 22:52:45 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2010/03/31 15:47:56 | 000,812,344 | —- | C] (Trend Micro Inc.) – C:\Program Files\HJTInstall.exe
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2010/12/12 14:38:00 | 000,000,629 | —- | M] () – C:\Documents and Settings\Hills\Desktop\Shortcut to OTL.lnk
[2010/12/12 14:16:09 | 000,000,422 | -H– | M] () – C:\WINDOWS\tasks\User_Feed_Synchronization-{10E034B1-B71A-4087-9E07-C1D0A21684BB}.job
[2010/12/12 14:10:00 | 000,000,884 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2010/12/12 12:51:16 | 000,000,281 | RHS- | M] () – C:\boot.ini
[2010/12/12 12:50:51 | 000,002,422 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2010/12/12 12:50:18 | 000,000,880 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2010/12/12 12:49:56 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2010/12/11 15:40:55 | 000,000,595 | —- | M] () – C:\Documents and Settings\All Users\Start Menu\Programs\Startup\NETGEAR WG111v2 Smart Wizard.lnk
[2010/12/11 15:40:55 | 000,000,583 | —- | M] () – C:\Documents and Settings\All Users\Desktop\NETGEAR WG111v2 Smart Wizard.lnk
[2010/12/11 12:05:34 | 000,493,384 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2010/12/11 12:05:34 | 000,083,802 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2010/12/11 11:21:15 | 000,001,700 | —- | M] () – C:\Documents and Settings\All Users\Desktop\avast! Free Antivirus.lnk
[2010/12/11 11:21:11 | 000,002,626 | —- | M] () – C:\WINDOWS\System32\CONFIG.NT
[2010/12/09 23:21:46 | 000,027,136 | —- | M] () – C:\Documents and Settings\Hills\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/12/07 21:29:37 | 000,122,928 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2010/12/07 17:00:44 | 000,000,885 | —- | M] () – C:\Documents and Settings\All Users\Desktop\OpenOffice.org 3.2.lnk
[2010/12/06 15:51:38 | 000,000,104 | —- | M] () – C:\Documents and Settings\Hills\Desktop\My Network Places.lnk
[2010/12/06 15:51:31 | 000,000,104 | —- | M] () – C:\Documents and Settings\Hills\Desktop\My Computer.lnk
[2010/12/05 11:24:06 | 000,000,800 | —- | M] () – C:\Documents and Settings\Hills\Application Data\Microsoft\Internet Explorer\Quick Launch\Windows Media Player.lnk
[2010/11/26 20:33:21 | 000,000,664 | —- | M] () – C:\WINDOWS\System32\d3d9caps.dat
[2010/11/22 14:20:31 | 000,002,447 | —- | M] () – C:\Documents and Settings\Hills\Desktop\HiJackThis.lnk
[2010/11/20 11:27:42 | 000,001,729 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Adobe Reader 9.lnk
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files Created - No Company Name ==========

[2010/12/12 14:38:00 | 000,000,629 | —- | C] () – C:\Documents and Settings\Hills\Desktop\Shortcut to OTL.lnk
[2010/12/11 15:40:58 | 000,036,864 | —- | C] () – C:\WINDOWS\System32\RtlGina2.dll
[2010/12/11 15:40:56 | 000,966,765 | —- | C] () – C:\WINDOWS\System32\acAuth.dll
[2010/12/11 15:40:56 | 000,344,064 | —- | C] () – C:\WINDOWS\System32\SCMLib.dll
[2010/12/11 15:40:55 | 000,000,595 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\Startup\NETGEAR WG111v2 Smart Wizard.lnk
[2010/12/11 15:40:55 | 000,000,583 | —- | C] () – C:\Documents and Settings\All Users\Desktop\NETGEAR WG111v2 Smart Wizard.lnk
[2010/12/07 17:00:44 | 000,000,885 | —- | C] () – C:\Documents and Settings\All Users\Desktop\OpenOffice.org 3.2.lnk
[2010/12/06 15:51:38 | 000,000,104 | —- | C] () – C:\Documents and Settings\Hills\Desktop\My Network Places.lnk
[2010/12/06 15:51:31 | 000,000,104 | —- | C] () – C:\Documents and Settings\Hills\Desktop\My Computer.lnk
[2010/12/05 11:24:06 | 000,000,800 | —- | C] () – C:\Documents and Settings\Hills\Application Data\Microsoft\Internet Explorer\Quick Launch\Windows Media Player.lnk
[2010/08/18 23:48:36 | 000,120,178 | —- | C] () – C:\Documents and Settings\LocalService\Local Settings\Application Data\WPFFontCache_v0400-System.dat
[2010/05/25 05:33:00 | 004,670,829 | —- | C] () – C:\WINDOWS\System32\libavcodec.dll
[2010/05/25 05:33:00 | 001,529,856 | —- | C] () – C:\WINDOWS\System32\ff_samplerate.dll
[2010/05/25 05:33:00 | 001,447,921 | —- | C] () – C:\WINDOWS\System32\ffmpegmt.dll
[2010/05/25 05:33:00 | 000,877,385 | —- | C] () – C:\WINDOWS\System32\ff_x264.dll
[2010/05/25 05:33:00 | 000,810,113 | —- | C] () – C:\WINDOWS\System32\xvidcore.dll
[2010/05/25 05:33:00 | 000,336,384 | —- | C] () – C:\WINDOWS\System32\ff_libfaad2.dll
[2010/05/25 05:33:00 | 000,324,096 | —- | C] () – C:\WINDOWS\System32\TomsMoComp_ff.dll
[2010/05/25 05:33:00 | 000,248,320 | —- | C] () – C:\WINDOWS\System32\ff_kernelDeint.dll
[2010/05/25 05:33:00 | 000,216,576 | —- | C] () – C:\WINDOWS\System32\ff_libdts.dll
[2010/05/25 05:33:00 | 000,151,552 | —- | C] () – C:\WINDOWS\System32\ff_libmad.dll
[2010/05/25 05:33:00 | 000,145,408 | —- | C] () – C:\WINDOWS\System32\libmpeg2_ff.dll
[2010/05/25 05:33:00 | 000,139,944 | —- | C] () – C:\WINDOWS\System32\libmplayer.dll
[2010/05/25 05:33:00 | 000,121,856 | —- | C] () – C:\WINDOWS\System32\ff_liba52.dll
[2010/05/25 05:33:00 | 000,116,736 | —- | C] () – C:\WINDOWS\System32\ff_tremor.dll
[2010/05/25 05:33:00 | 000,108,032 | —- | C] () – C:\WINDOWS\System32\ff_vfw.dll
[2010/05/25 05:33:00 | 000,100,864 | —- | C] () – C:\WINDOWS\System32\ff_wmv9.dll
[2010/05/25 05:33:00 | 000,097,792 | —- | C] () – C:\WINDOWS\System32\ff_unrar.dll
[2010/05/20 06:59:20 | 000,150,528 | —- | C] () – C:\WINDOWS\System32\mkx.dll
[2010/05/20 06:59:10 | 000,109,568 | —- | C] () – C:\WINDOWS\System32\avi.dll
[2010/05/20 06:59:02 | 000,141,824 | —- | C] () – C:\WINDOWS\System32\mp4.dll
[2010/05/20 06:58:52 | 000,123,392 | —- | C] () – C:\WINDOWS\System32\ogm.dll
[2010/05/20 06:58:18 | 000,154,112 | —- | C] () – C:\WINDOWS\System32\ts.dll
[2010/05/20 06:58:08 | 000,249,856 | —- | C] () – C:\WINDOWS\System32\dxr.dll
[2010/05/20 06:57:42 | 000,097,792 | —- | C] () – C:\WINDOWS\System32\avs.dll
[2010/05/20 06:57:26 | 000,093,184 | —- | C] () – C:\WINDOWS\System32\avss.dll
[2010/05/20 06:55:40 | 000,080,384 | —- | C] () – C:\WINDOWS\System32\mkzlib.dll
[2010/05/20 06:55:36 | 000,024,576 | —- | C] () – C:\WINDOWS\System32\mkunicode.dll
[2010/03/30 18:41:59 | 000,000,069 | —- | C] () – C:\WINDOWS\NeroDigital.ini
[2010/01/07 15:00:23 | 000,000,205 | —- | C] () – C:\WINDOWS\youtube2mp3.ini
[2009/11/11 13:20:49 | 000,000,000 | —- | C] () – C:\Documents and Settings\Hills\Local Settings\Application Data\prvlcl.dat
[2009/11/07 10:42:49 | 000,034,915 | —- | C] () – C:\WINDOWS\System32\1_ssetup.ini
[2009/11/07 10:42:49 | 000,016,819 | —- | C] () – C:\WINDOWS\System32\sunistlog.ini
[2009/11/07 10:40:21 | 000,155,648 | —- | C] () – C:\WINDOWS\System32\setuplib.dll
[2009/09/23 01:25:30 | 000,027,136 | —- | C] () – C:\Documents and Settings\Hills\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/07/22 10:13:14 | 000,005,606 | R— | C] () – C:\WINDOWS\System32\stci.dll
[2009/07/21 22:20:41 | 000,155,648 | R— | C] () – C:\WINDOWS\System32\TVModeLib.dll
[2009/07/21 22:20:17 | 000,121,948 | —- | C] () – C:\WINDOWS\VGAsetup.ini
[2009/07/21 22:20:00 | 000,108,562 | —- | C] () – C:\WINDOWS\System32\VGAunistlog.ini
[2009/07/21 19:18:39 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2009/06/08 02:24:04 | 000,180,224 | —- | C] () – C:\WINDOWS\System32\xvidvfw.dll
[2009/01/11 08:15:44 | 000,159,744 | —- | C] () – C:\WINDOWS\System32\mmfinfo.dll
[2008/11/07 01:37:32 | 003,596,288 | —- | C] () – C:\WINDOWS\System32\qt-dx331.dll
[2007/10/13 19:30:20 | 000,000,137 | —- | C] () – C:\WINDOWS\System32\Registration.ini

========== LOP Check ==========

[2010/06/20 13:28:31 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Alwil Software
[2010/10/09 17:38:56 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\DFX
[2010/02/07 14:48:54 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2010/07/24 16:37:07 | 000,000,000 | —D | M] – C:\Documents and Settings\Hills\Application Data\DVDVideoSoftIEHelpers
[2009/07/22 00:02:20 | 000,000,000 | —D | M] – C:\Documents and Settings\Hills\Application Data\OpenOffice.org
[2010/12/09 23:05:44 | 000,000,000 | —D | M] – C:\Documents and Settings\Hills\Application Data\uTorrent
[2010/12/12 14:16:09 | 000,000,422 | -H– | M] () – C:\WINDOWS\Tasks\User_Feed_Synchronization-{10E034B1-B71A-4087-9E07-C1D0A21684BB}.job

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2009/07/21 09:34:02 | 000,000,000 | —- | M] () – C:\AUTOEXEC.BAT
[2010/12/12 12:51:16 | 000,000,281 | RHS- | M] () – C:\boot.ini
[2010/11/26 20:02:18 | 000,013,486 | —- | M] () – C:\ComboFix.txt
[2009/07/21 09:34:02 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2009/07/21 09:34:02 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2010/08/24 18:46:51 | 000,000,444 | —- | M] () – C:\JavaRa.log
[2009/07/21 09:34:02 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2007/07/27 22:00:00 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2009/07/21 22:35:20 | 000,250,048 | RHS- | M] () – C:\ntldr
[2010/12/12 12:49:51 | 754,974,720 | -HS- | M] () – C:\pagefile.sys

< %systemroot%\Fonts\*.com >
[2006/04/18 15:39:28 | 000,026,040 | —- | M] () – C:\WINDOWS\Fonts\GlobalMonospace.CompositeFont
[2006/06/29 14:53:56 | 000,026,489 | —- | M] () – C:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont
[2006/04/18 15:39:28 | 000,029,779 | —- | M] () – C:\WINDOWS\Fonts\GlobalSerif.CompositeFont
[2006/06/29 14:58:52 | 000,030,808 | —- | M] () – C:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2009/07/21 09:33:10 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2008/07/06 22:06:10 | 000,089,088 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2008/07/06 20:50:03 | 000,597,504 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >
[2010/09/08 01:12:17 | 000,038,848 | —- | M] (AVAST Software) – C:\WINDOWS\avastSS.scr

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >
[2010/03/31 15:48:14 | 000,812,344 | —- | M] (Trend Micro Inc.) – C:\Program Files\HJTInstall.exe

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >
[2009/07/21 19:16:17 | 000,094,208 | —- | M] () – C:\WINDOWS\system32\config\default.sav
[2009/07/21 19:16:17 | 000,659,456 | —- | M] () – C:\WINDOWS\system32\config\software.sav
[2009/07/21 19:16:17 | 000,868,352 | —- | M] () – C:\WINDOWS\system32\config\system.sav

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
[2009/07/21 22:42:38 | 000,000,272 | -HS- | M] () – C:\Documents and Settings\All Users\Start Menu\desktop.ini

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2009/07/21 22:55:49 | 000,000,119 | -HS- | M] () – C:\Documents and Settings\Hills\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini

< %USERPROFILE%\Desktop\*.exe >

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< %APPDATA%\Roaming\Microsoft\Windows\Recent\*.lnk /x >

< %PROGRAMFILES%\PC-Doctor\Downloads\*.* >

< %PROGRAMFILES%\Internet Explorer\*.tmp >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %USERPROFILE%\My Documents\*.exe >

< %USERPROFILE%\*.exe >

< %systemroot%\ADDINS\*.* >

< %systemroot%\assembly\*.bak2 >

< %systemroot%\Config\*.* >

< %systemroot%\REPAIR\*.bak2 >

< %systemroot%\SECURITY\Database\*.sdb /x >

< %systemroot%\SYSTEM\*.bak2 >

< %systemroot%\Web\*.bak2 >

< %systemroot%\Driver Cache\*.* >

< %PROGRAMFILES%\Mozilla Firefox\0*.exe >

< %ProgramFiles%\Microsoft Common\*.* >

< %ProgramFiles%\TinyProxy. >

< %USERPROFILE%\Favorites\*.url /x >
[2009/07/21 22:55:50 | 000,000,122 | -HS- | M] () – C:\Documents and Settings\Hills\Favorites\Desktop.ini

< %systemroot%\system32\*.bk >

< %systemroot%\*.te >

< %systemroot%\system32\system32\*.* >

< %ALLUSERSPROFILE%\*.dat /x >

< %systemroot%\system32\drivers\*.rmv >

< dir /b "%systemroot%\system32\*.exe" | find /i " " /c >

< dir /b "%systemroot%\*.exe" | find /i " " /c >

< %PROGRAMFILES%\Microsoft\*.* >

< %systemroot%\System32\Wbem\proquota.exe >

< %PROGRAMFILES%\Mozilla Firefox\*.dat >

< %USERPROFILE%\Cookies\*.txt /x >
[2010/12/12 14:15:59 | 000,032,768 | -HS- | M] () – C:\Documents and Settings\Hills\Cookies\index.dat

< %SystemRoot%\system32\fonts\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2010-12-05 07:07:45

========== Alternate Data Streams ==========

@Alternate Data Stream - 16 bytes -> C:\WINDOWS\System32\mswinsck32.ocx:rsrc
@Alternate Data Stream - 110 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:DFC5A2B2

< End of report >






OTL Extras logfile created on: 12/12/2010 2:39:11 PM - Run 1
OTL by OldTimer - Version 3.2.17.3 Folder = C:\Documents and Settings\Hills\My Documents\Downloads
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000C09 | Country: Australia | Language: ENA | Date Format: d/MM/yyyy

224.00 Mb Total Physical Memory | 117.00 Mb Available Physical Memory | 52.00% Memory free
931.00 Mb Paging File | 768.00 Mb Available in Paging File | 82.00% Paging File free
Paging file location(s): C:\pagefile.sys 720 1440 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 37.26 Gb Total Space | 7.18 Gb Free Space | 19.26% Space Free | Partition Type: NTFS

Computer Name: YEOLDINN | User Name: Hills | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
htmlfile – Reg Error: Key error.
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Disabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Disabled:@xpsp2res.dll,-22008

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\Google\Google Earth\plugin\geplugin.exe" = C:\Program Files\Google\Google Earth\plugin\geplugin.exe:*:Enabled:Google Earth – (Google)
"C:\Program Files\uTorrent\uTorrent.exe" = C:\Program Files\uTorrent\uTorrent.exe:*:Enabled:µTorrent – (BitTorrent, Inc.)


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0A0CADCF-78DA-33C4-A350-CD51849B9702}" = Microsoft .NET Framework 4 Extended
"{0AAA9C97-74D4-47CE-B089-0B147EF3553C}" = Windows Live Messenger
"{171E6C1E-B5FC-11DF-B115-005056C00008}" = Google Earth Plug-in
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{26A24AE4-039D-4CA4-87B4-2F83216021FF}" = Java™ 6 Update 21
"{33CF58F5-48D8-4575-83D6-96F574E4D83A}" = Nero DriveSpeed
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{359CFC0A-BEB1-440D-95BA-CF63A86DA34F}" = Nero Recode
"{368BA326-73AD-4351-84ED-3C0A7A52CC53}" = Nero Rescue Agent
"{3B4E636E-9D65-4D67-BA61-189800823F52}" = Windows Live Communications Platform
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{4102037D-E8E0-48E0-B203-E521D194FB71}" = NETGEAR WG111v2 wireless USB 2.0 adapter
"{43E39830-1826-415D-8BAE-86845787B54B}" = Nero Vision
"{45A66726-69BC-466B-A7A4-12FCBA4883D7}" = HiJackThis
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4DE3E3D9-AE81-45DE-9195-3015F7B1DBF3}" = Junk Mail filter update
"{56C049BE-79E9-4502-BEA7-9754A3E60F9B}" = neroxml
"{595A3116-40BB-4E0F-A2E8-D7951DA56270}" = NeroExpress
"{62AC81F6-BDD3-4110-9D36-3E9EAAB40999}" = Nero CoverDesigner
"{63C1109E-D977-49ED-BCE3-D00D0BF187D6}" = Windows Live Mail
"{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD
"{6A92E5C5-0578-443D-91F3-92ECE5F2CAE2}" = Windows Live Writer
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{7748AC8C-18E3-43BB-959B-088FAEA16FB2}" = Nero StartSmart
"{7829DB6F-A066-4E40-8912-CB07887C20BB}" = Nero BurnRights
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{869200DB-287A-4DC0-B02B-2B6787FBCD4C}" = Nero DiscSpeed
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8FFC5648-FAF8-43A3-BC8F-42BA1E275C4E}" = Choice Guard
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{9E82B934-9A25-445B-B8DF-8012808074AC}" = Nero PhotoSnap
"{A1F66FC9-11EE-4F2F-98C9-16F8D1E69FB7}" = Segoe UI
"{A209525B-3377-43F4-B886-32F6B6E7356F}" = Nero WaveEditor
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A8F2089B-1F79-4BF6-B385-A2C2B0B9A74D}" = ImagXpress
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AC76BA86-7AD7-1033-7B44-A94000000001}" = Adobe Reader 9.4.1
"{B2EC4A38-B545-4A00-8214-13FE0E915E6D}" = Advertising Center
"{B78120A0-CF84-4366-A393-4D0A59BC546C}" = Menu Templates - Starter Kit
"{BD5CA0DA-71AD-43DA-B19E-6EEE0C9ADC9A}" = Nero ControlCenter
"{BEFBEDDF-1417-4C8A-92FB-F003C0D41199}" = OpenOffice.org 3.2
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C5A7CB6C-E76D-408F-BA0E-85605420FE9D}" = SoundTrax
"{C6CA8874-5F22-4AF0-9BE3-016BF299C536}" = Windows Live Essentials
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D025A639-B9C9-417D-8531-208859000AF8}" = NeroBurningROM
"{D9DCF92E-72EB-412D-AC71-3B01276E5F8B}" = Nero ShowTime
"{E2883E8F-472F-4fb0-9522-AC9BF37916A7}" = Adobe Download Manager
"{E498385E-1C51-459A-B45F-1721E37AA1A0}" = Movie Templates - Starter Kit
"{E8A80433-302B-4FF1-815D-FCC8EAC482FF}" = Nero Installer
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}" = Visual C++ 2008 x86 Runtime - (v9.0.30729)
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}.vc_x86runtime_30729_01" = Visual C++ 2008 x86 Runtime - v9.0.30729.01
"{F6BD194C-4190-4D73-B1B1-C48C99921BFE}" = Windows Live Call
"{FBCDFD61-7DCF-4E71-9226-873BA0053139}" = Nero InfoTool
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"avast5" = avast! Free Antivirus
"CCleaner" = CCleaner
"Defraggler" = Defraggler
"DFX for Windows Media Player" = DFX for Windows Media Player
"Free YouTube to MP3 Converter_is1" = Free YouTube to MP3 Converter version 3.8
"GOM Player" = GOM Player
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"ie8" = Windows Internet Explorer 8
"Media Player - Codec Pack" = Media Player Codec Pack 3.9.6
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 4 Extended" = Microsoft .NET Framework 4 Extended
"Mozilla Firefox (3.6.12)" = Mozilla Firefox (3.6.12)
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"SiS VGA Utilities" = SiS VGA Utilities
"uTorrent" = µTorrent
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 3
"WinLiveSuite_Wave3" = Windows Live Essentials
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 26/11/2010 6:22:07 AM | Computer Name = YEOLDINN | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: This network connection does not exist.

Error - 26/11/2010 6:22:10 AM | Computer Name = YEOLDINN | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: This network connection does not exist.

Error - 26/11/2010 6:22:12 AM | Computer Name = YEOLDINN | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: This network connection does not exist.

Error - 26/11/2010 6:22:15 AM | Computer Name = YEOLDINN | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: This network connection does not exist.

Error - 26/11/2010 6:22:15 AM | Computer Name = YEOLDINN | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: This network connection does not exist.

Error - 26/11/2010 6:22:19 AM | Computer Name = YEOLDINN | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: This network connection does not exist.

Error - 26/11/2010 6:22:33 AM | Computer Name = YEOLDINN | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: The server name or address could not be resolved

Error - 4/12/2010 12:47:56 AM | Computer Name = YEOLDINN | Source = MSDTC | ID = 4163
Description = MS DTC log file not found. After ensuring that all Resource Managers
coordinated by MS DTC have no indoubt transactions, please run msdtc -resetlog
to create the log fil

Error - 4/12/2010 12:47:56 AM | Computer Name = YEOLDINN | Source = MSDTC | ID = 4185
Description = MS DTC Transaction Manager start failed. LogInit returned error 0x

Error - 4/12/2010 12:47:56 AM | Computer Name = YEOLDINN | Source = MSDTC | ID = 4112
Description = Could not start the MS DTC Transaction Manage

[ System Events ]
Error - 10/12/2010 9:21:12 PM | Computer Name = YEOLDINN | Source = Service Control Manager | ID = 7006
Description = The ScRegSetValueExW call failed for FailureActions with the following
error: %%5

Error - 10/12/2010 9:21:12 PM | Computer Name = YEOLDINN | Source = Service Control Manager | ID = 7006
Description = The ScRegSetValueExW call failed for FailureActions with the following
error: %%5

Error - 10/12/2010 10:04:22 PM | Computer Name = YEOLDINN | Source = W32Time | ID = 39452689
Description = Time Provider NtpClient: An error occurred during DNS lookup of the
manually configured peer 'time.windows.com,0x1'. NtpClient will try the DNS lookup
again in 15 minutes. The error was: A socket operation was attempted to an unreachable
host. (0x80072751)

Error - 10/12/2010 10:04:22 PM | Computer Name = YEOLDINN | Source = W32Time | ID = 39452701
Description = The time provider NtpClient is configured to acquire time from one
or more time sources, however none of the sources are currently accessible. No attempt
to contact a source will be made for 14 minutes. NtpClient has no source of accurate
time.

Error - 10/12/2010 11:12:45 PM | Computer Name = YEOLDINN | Source = DCOM | ID = 10010
Description = The server {F81CD990-910B-4BBF-9CB3-6A77F3D697B3} did not register
with DCOM within the required timeout.

Error - 10/12/2010 11:40:26 PM | Computer Name = YEOLDINN | Source = W32Time | ID = 39452689
Description = Time Provider NtpClient: An error occurred during DNS lookup of the
manually configured peer 'time.windows.com,0x1'. NtpClient will try the DNS lookup
again in 15 minutes. The error was: A socket operation was attempted to an unreachable
host. (0x80072751)

Error - 10/12/2010 11:40:26 PM | Computer Name = YEOLDINN | Source = W32Time | ID = 39452701
Description = The time provider NtpClient is configured to acquire time from one
or more time sources, however none of the sources are currently accessible. No attempt
to contact a source will be made for 14 minutes. NtpClient has no source of accurate
time.

Error - 11/12/2010 1:49:21 AM | Computer Name = YEOLDINN | Source = Service Control Manager | ID = 7006
Description = The ScRegSetValueExW call failed for Start with the following error:
%%5

Error - 11/12/2010 1:49:21 AM | Computer Name = YEOLDINN | Source = Service Control Manager | ID = 7006
Description = The ScRegSetValueExW call failed for Start with the following error:
%%5

Error - 11/12/2010 1:49:21 AM | Computer Name = YEOLDINN | Source = Service Control Manager | ID = 7006
Description = The ScRegSetValueExW call failed for Start with the following error:
%%5


< End of report >
Hi free,

P2P - I see you have P2P software uTorrent installed on your machine. We are not here to pass judgment on file-sharing as a concept. However, we will warn you that engaging in this activity and having this kind of software installed on your machine will always make you more susceptible to re-infections. It likely contributed to your current situation. This page will give you further information.
Please note: Even if you are using a "safe" P2P program, it is only the program that is safe. You will be sharing files from uncertified sources, and these are often infected. The bad guys use P2P filesharing as a major conduit to spread their wares.
Please see this topic for more information:
Perils of P2P File Sharing.
I would strongly recommend that you uninstall these now. You can do so via Control Panel >> Add or Remove Programs.

Peer to Peer Program
While reviewing your logs I noticed that you currently have Peer to Peer program(s) installed on your computer.

You currently have the following P2P programs installed:
  • Program 1
  • Program 2
Most of the infections that we see today are through P2P file sharing. By uninstalling the programs that I mentioned above you will be doing yourself a favor. It's impossible to trust the source of what is being downloaded from them and a file may or may not be what it appears to be.

Should you decide to keep these programs installed on your computer PLEASE do not use these programs while we are getting your P.C. cleaned up.

Please go to: VirusTotal
  • [external image: Posted Image]
  • Click the Browse button and search for the following file: C:\WINDOWS\System32\drivers\pqnersy.sys
  • Click Open
  • Then click Send File
  • Please be patient while the file is scanned.
  • Once the scan results appear, please provide them in your next reply.
If it says already scanned – click "reanalyze now"

Please post the results in your next reply.

===================================================

Scan With RootKitUnHooker

  • Please Download Rootkit Unhooker and save it to your desktop.
  • Now double-click on RKUnhookerLE.exe to run it.
  • Click the Report tab, then click Scan.
  • Check (Tick) Drivers and Stealth
  • Uncheck the rest. then click OK
  • When prompted to Select Disks for Scan, make sure C:\ is checked and click OK
  • Wait till the scanner has finished and then click File > Save Report.
  • Save the report somewhere where you can find it. Click Close.
  • Copy the entire contents of the report and paste it in your next reply.

Note** you may get the following warning, just click OK and continue.

"Rootkit Unhooker has detected a parasite inside itself!
It is recommended to remove parasite, okay?"


===================================================

Please download MBRCheck.exe to your desktop.
  • Be sure to disable your security programs
  • Double click on the file to run it (Vista and Windows 7 users will have to confirm the UAC prompt)
  • A window will open on your desktop
  • if an unknown bootcode is found you will have further options available to you, at this time press N then press Enter twice.
  • If nothing unusual is found just press Enter
  • A .txt file named MBRCheck_mm.dd.yy_hh.mm.ss should appear on your desktop.
  • Please post the contents of that file.
===================================================

In your next reply, post the following:
Results of Virus TOTAL Scan
Rootkit Unhooker Log
MBR Check log
Hey NoodleTech, thanks for the advice. I was just a bit unsure how to uninstall Program 1 & 2, I couldn't find them in add/remove programs. What exactly are they?? or what is there names, u said they were P2P file sharing? Anyway I will post the results of the scans shortly. Cheers Free
Hey, I have done the MBR check and posted the log below. I had a problem with your link for rootkit unhooker and virus total. Directed me to a website not found page? Anyhow I got onto the virus total website and couldn't find the file that u requested, it wasn't there?? C:\WINDOWS\System32\drivers\pqnersy.sys Can you re post those links again! Sorry for any inconvenience. Cheers Free MBRCheck, version 1.2.3 © 2010, AD Command-line: Windows Version: Windows XP Professional Windows Information: Service Pack 3 (build 2600) Logical Drives Mask: 0x0000001d Kernel Drivers (total 110): 0x804D7000 \WINDOWS\system32\ntoskrnl.exe 0x806EE000 \WINDOWS\system32\hal.dll 0xFA3AC000 \WINDOWS\system32\KDCOM.DLL 0xFA2BC000 \WINDOWS\system32\BOOTVID.dll 0xF9E5D000 ACPI.sys 0xFA3AE000 \WINDOWS\system32\DRIVERS\WMILIB.SYS 0xF9E4C000 pci.sys 0xF9EAC000 isapnp.sys 0xFA474000 pciide.sys 0xFA12C000 \WINDOWS\system32\DRIVERS\PCIIDEX.SYS 0xF9EBC000 MountMgr.sys 0xF9E2D000 ftdisk.sys 0xFA3B0000 dmload.sys 0xF9E07000 dmio.sys 0xFA134000 PartMgr.sys 0xF9ECC000 VolSnap.sys 0xF9DEF000 atapi.sys 0xF9EDC000 disk.sys 0xF9EEC000 \WINDOWS\system32\DRIVERS\CLASSPNP.SYS 0xF9DCF000 fltmgr.sys 0xF9DBD000 sr.sys 0xF9DA6000 KSecDD.sys 0xF9D93000 WudfPf.sys 0xF9D06000 Ntfs.sys 0xF9CD9000 NDIS.sys 0xFA13C000 SISAGPX.sys 0xF9CBF000 Mup.sys 0xFA03C000 \SystemRoot\system32\DRIVERS\intelppm.sys 0xF9C4B000 \SystemRoot\system32\DRIVERS\sisgrp.sys 0xF9C37000 \SystemRoot\system32\DRIVERS\VIDEOPRT.SYS 0xFA19C000 \SystemRoot\system32\DRIVERS\fdc.sys 0xF9C23000 \SystemRoot\system32\DRIVERS\parport.sys 0xFA04C000 \SystemRoot\system32\DRIVERS\serial.sys 0xFA368000 \SystemRoot\system32\DRIVERS\serenum.sys 0xFA05C000 \SystemRoot\system32\DRIVERS\i8042prt.sys 0xFA1A4000 \SystemRoot\system32\DRIVERS\kbdclass.sys 0xFA1AC000 \SystemRoot\system32\DRIVERS\mouclass.sys 0xFA36C000 \SystemRoot\system32\DRIVERS\gameenum.sys 0xFA1B4000 \SystemRoot\system32\DRIVERS\usbohci.sys 0xF9BFF000 \SystemRoot\system32\DRIVERS\USBPORT.SYS 0xFA06C000 \SystemRoot\system32\DRIVERS\imapi.sys 0xFA07C000 \SystemRoot\system32\DRIVERS\cdrom.sys 0xFA08C000 \SystemRoot\system32\DRIVERS\redbook.sys 0xF9BDC000 \SystemRoot\system32\DRIVERS\ks.sys 0xF9BB0000 \SystemRoot\system32\drivers\sis7012.sys 0xF9B8C000 \SystemRoot\system32\drivers\portcls.sys 0xFA09C000 \SystemRoot\system32\drivers\drmk.sys 0xFA586000 \SystemRoot\system32\DRIVERS\audstub.sys 0xFA0AC000 \SystemRoot\system32\DRIVERS\rasl2tp.sys 0xFA378000 \SystemRoot\system32\DRIVERS\ndistapi.sys 0xF9B75000 \SystemRoot\system32\DRIVERS\ndiswan.sys 0xFA0BC000 \SystemRoot\system32\DRIVERS\raspppoe.sys 0xFA0CC000 \SystemRoot\system32\DRIVERS\raspptp.sys 0xFA1BC000 \SystemRoot\system32\DRIVERS\TDI.SYS 0xF9B3C000 \SystemRoot\system32\DRIVERS\psched.sys 0xFA0DC000 \SystemRoot\system32\DRIVERS\msgpc.sys 0xFA1C4000 \SystemRoot\system32\DRIVERS\ptilink.sys 0xFA1CC000 \SystemRoot\system32\DRIVERS\raspti.sys 0xF9B0C000 \SystemRoot\system32\DRIVERS\rdpdr.sys 0xFA0EC000 \SystemRoot\system32\DRIVERS\termdd.sys 0xFA3C6000 \SystemRoot\system32\DRIVERS\swenum.sys 0xF9AAE000 \SystemRoot\system32\DRIVERS\update.sys 0xFA394000 \SystemRoot\system32\DRIVERS\mssmbios.sys 0xFA0FC000 \SystemRoot\System32\Drivers\NDProxy.SYS 0xFA1D4000 \SystemRoot\system32\DRIVERS\flpydisk.sys 0xF9F2C000 \SystemRoot\system32\DRIVERS\usbhub.sys 0xFA3C8000 \SystemRoot\system32\DRIVERS\USBD.SYS 0xFA3CA000 \SystemRoot\System32\Drivers\Fs_Rec.SYS 0xFA5F7000 \SystemRoot\System32\Drivers\Null.SYS 0xFA3CC000 \SystemRoot\System32\Drivers\Beep.SYS 0xFA1E4000 \SystemRoot\System32\drivers\vga.sys 0xFA3CE000 \SystemRoot\System32\Drivers\mnmdd.SYS 0xFA3D0000 \SystemRoot\System32\DRIVERS\RDPCDD.sys 0xFA1EC000 \SystemRoot\System32\Drivers\Msfs.SYS 0xFA1F4000 \SystemRoot\System32\Drivers\Npfs.SYS 0xF9C8B000 \SystemRoot\system32\DRIVERS\rasacd.sys 0xEE994000 \SystemRoot\system32\DRIVERS\ipsec.sys 0xEE93B000 \SystemRoot\system32\DRIVERS\tcpip.sys 0xF9F3C000 \SystemRoot\System32\Drivers\aswTdi.SYS 0xEE913000 \SystemRoot\system32\DRIVERS\netbt.sys 0xEE8F1000 \SystemRoot\System32\drivers\afd.sys 0xF9F4C000 \SystemRoot\system32\DRIVERS\netbios.sys 0xEE8C6000 \SystemRoot\system32\DRIVERS\rdbss.sys 0xEE82E000 \SystemRoot\system32\DRIVERS\mrxsmb.sys 0xF9F5C000 \SystemRoot\System32\Drivers\Fips.SYS 0xEE808000 \SystemRoot\system32\DRIVERS\ipnat.sys 0xF9F6C000 \SystemRoot\system32\DRIVERS\wanarp.sys 0xEE79E000 \SystemRoot\System32\Drivers\aswSP.SYS 0xFA20C000 \SystemRoot\System32\Drivers\Aavmker4.SYS 0xF9F8C000 \SystemRoot\System32\Drivers\Cdfs.SYS 0xBF800000 \SystemRoot\System32\win32k.sys 0xF9B55000 \SystemRoot\System32\drivers\Dxapi.sys 0xFA214000 \SystemRoot\System32\watchdog.sys 0xBF000000 \SystemRoot\System32\drivers\dxg.sys 0xFA510000 \SystemRoot\System32\drivers\dxgthk.sys 0xBF012000 \SystemRoot\System32\SiSGRV.dll 0xBFFA0000 \SystemRoot\System32\ATMFD.DLL 0xEC6CA000 \SystemRoot\System32\Drivers\aswFsBlk.SYS 0xFA15C000 \SystemRoot\system32\DRIVERS\AegisP.sys 0xEC646000 \SystemRoot\system32\DRIVERS\ndisuio.sys 0xEC41F000 \SystemRoot\System32\Drivers\aswMon2.SYS 0xEC14A000 \SystemRoot\system32\DRIVERS\mrxdav.sys 0xEC095000 \SystemRoot\system32\drivers\wdmaud.sys 0xF1A56000 \SystemRoot\system32\drivers\sysaudio.sys 0xFA3B4000 \SystemRoot\System32\Drivers\ParVdm.SYS 0xF995E000 \SystemRoot\system32\DRIVERS\srv.sys 0xF9675000 \SystemRoot\System32\Drivers\HTTP.sys 0xF951A000 \SystemRoot\system32\DRIVERS\wg111v2.sys 0xEC01F000 \SystemRoot\system32\drivers\kmixer.sys 0x7C900000 \WINDOWS\system32\ntdll.dll Processes (total 25): 0 System Idle Process 4 System 396 C:\WINDOWS\system32\smss.exe 452 csrss.exe 476 C:\WINDOWS\system32\winlogon.exe 520 C:\WINDOWS\system32\services.exe 532 C:\WINDOWS\system32\lsass.exe 692 C:\WINDOWS\system32\svchost.exe 760 svchost.exe 800 C:\WINDOWS\system32\svchost.exe 836 C:\WINDOWS\system32\svchost.exe 900 svchost.exe 928 svchost.exe 1116 C:\Program Files\Alwil Software\Avast5\AvastSvc.exe 1268 C:\WINDOWS\explorer.exe 1384 C:\Program Files\Alwil Software\Avast5\AvastUI.exe 1392 C:\WINDOWS\system32\ctfmon.exe 1404 C:\Program Files\NETGEAR\WG111v2\WG111v2.exe 1660 C:\WINDOWS\system32\spoolsv.exe 1724 svchost.exe 1992 C:\Program Files\Google\Update\GoogleUpdate.exe 1164 C:\WINDOWS\system32\wscntfy.exe 756 alg.exe 784 C:\Program Files\Adobe\Reader 9.0\Reader\AcroRd32Info.exe 2292 C:\Documents and Settings\Hills\My Documents\Downloads\MBRCheck.exe \\.\C: –> \\.\PhysicalDrive0 at offset 0x00000000`00007e00 (NTFS) PhysicalDrive0 Model Number: ST340016A, Rev: 3.19 Size Device Name MBR Status ——————————————– 37 GB \\.\PhysicalDrive0 Windows XP MBR code detected SHA1: DA38B874B7713D1B51CBC449F4EF809B0DEC644A Done!
Hi free,

Sorry about the links not working. I posted outdated links.

Scan With RootKitUnHooker

  • Please choose one link and download Rootkit Unhooker and save it to your desktop.
    Link 1
    Link 2
    Link 3
  • Now double-click on RKUnhookerLE.exe to run it.
  • Click the Report tab, then click Scan.
  • Check (Tick) Drivers and Stealth
  • Uncheck the rest. then click OK
  • When prompted to Select Disks for Scan, make sure C:\ is checked and click OK
  • Wait till the scanner has finished and then click File > Save Report.
  • Save the report somewhere where you can find it. Click Close.
  • Copy the entire contents of the report and paste it in your next reply.

Note** you may get the following warning, just click OK and continue.

"Rootkit Unhooker has detected a parasite inside itself!
It is recommended to remove parasite, okay?"


===================================================

Now let's see if we can locate the file after enabling hidden files and folders.

To enable the viewing of Hidden files follow these steps:
  • Close all programs so that you are at your desktop.
  • Double-click on the My Computer icon.
  • Select the Tools menu and click Folder Options.
  • After the new window appears select the View tab.
  • Put a checkmark in the checkbox labeled Display the contents of system folders.
  • Under the Hidden files and folders section select the radio button labeled Show hidden files and folders.
  • Remove the checkmark from the checkbox labeled Hide file extensions for known file types.
  • Remove the checkmark from the checkbox labeled Hide protected operating system files.
  • Press the Apply button and then the OK button and close My Computer.
  • Now your computer is configured to show all hidden files.

Now go to: VirusTotal
  • [external image: Posted Image]
  • Click the Browse button and search for the following file: C:\WINDOWS\System32\drivers\pqnersy.sys
  • Click Open
  • Then click Send File
  • Please be patient while the file is scanned.
  • Once the scan results appear, please provide them in your next reply.
If it says already scanned – click "reanalyze now"

Please post the results in your next reply.
Hey, Here are the logs. I am still having trouble finding that file C:\WINDOWS\System32\drivers\pqnersy.sys. Even after i have checked the appropriate boxes for Hidden Files & Folder Options. MBRCheck, version 1.2.3 © 2010, AD Command-line: Windows Version: Windows XP Professional Windows Information: Service Pack 3 (build 2600) Logical Drives Mask: 0x0000001d Kernel Drivers (total 112): 0x804D7000 \WINDOWS\system32\ntoskrnl.exe 0x806EE000 \WINDOWS\system32\hal.dll 0xFA3AC000 \WINDOWS\system32\KDCOM.DLL 0xFA2BC000 \WINDOWS\system32\BOOTVID.dll 0xF9E5D000 ACPI.sys 0xFA3AE000 \WINDOWS\system32\DRIVERS\WMILIB.SYS 0xF9E4C000 pci.sys 0xF9EAC000 isapnp.sys 0xFA474000 pciide.sys 0xFA12C000 \WINDOWS\system32\DRIVERS\PCIIDEX.SYS 0xF9EBC000 MountMgr.sys 0xF9E2D000 ftdisk.sys 0xFA3B0000 dmload.sys 0xF9E07000 dmio.sys 0xFA134000 PartMgr.sys 0xF9ECC000 VolSnap.sys 0xF9DEF000 atapi.sys 0xF9EDC000 disk.sys 0xF9EEC000 \WINDOWS\system32\DRIVERS\CLASSPNP.SYS 0xF9DCF000 fltmgr.sys 0xF9DBD000 sr.sys 0xF9DA6000 KSecDD.sys 0xF9D93000 WudfPf.sys 0xF9D06000 Ntfs.sys 0xF9CD9000 NDIS.sys 0xFA13C000 SISAGPX.sys 0xF9CBF000 Mup.sys 0xFA02C000 \SystemRoot\system32\DRIVERS\intelppm.sys 0xF977B000 \SystemRoot\system32\DRIVERS\sisgrp.sys 0xF9767000 \SystemRoot\system32\DRIVERS\VIDEOPRT.SYS 0xFA1C4000 \SystemRoot\system32\DRIVERS\fdc.sys 0xF9753000 \SystemRoot\system32\DRIVERS\parport.sys 0xFA03C000 \SystemRoot\system32\DRIVERS\serial.sys 0xFA388000 \SystemRoot\system32\DRIVERS\serenum.sys 0xFA04C000 \SystemRoot\system32\DRIVERS\i8042prt.sys 0xFA1CC000 \SystemRoot\system32\DRIVERS\kbdclass.sys 0xFA1D4000 \SystemRoot\system32\DRIVERS\mouclass.sys 0xFA38C000 \SystemRoot\system32\DRIVERS\gameenum.sys 0xFA1DC000 \SystemRoot\system32\DRIVERS\usbohci.sys 0xF972F000 \SystemRoot\system32\DRIVERS\USBPORT.SYS 0xFA05C000 \SystemRoot\system32\DRIVERS\imapi.sys 0xFA06C000 \SystemRoot\system32\DRIVERS\cdrom.sys 0xFA07C000 \SystemRoot\system32\DRIVERS\redbook.sys 0xF970C000 \SystemRoot\system32\DRIVERS\ks.sys 0xF96E0000 \SystemRoot\system32\drivers\sis7012.sys 0xF96BC000 \SystemRoot\system32\drivers\portcls.sys 0xFA08C000 \SystemRoot\system32\drivers\drmk.sys 0xFA5A2000 \SystemRoot\system32\DRIVERS\audstub.sys 0xFA09C000 \SystemRoot\system32\DRIVERS\rasl2tp.sys 0xFA39C000 \SystemRoot\system32\DRIVERS\ndistapi.sys 0xF96A5000 \SystemRoot\system32\DRIVERS\ndiswan.sys 0xFA0AC000 \SystemRoot\system32\DRIVERS\raspppoe.sys 0xFA0BC000 \SystemRoot\system32\DRIVERS\raspptp.sys 0xFA1E4000 \SystemRoot\system32\DRIVERS\TDI.SYS 0xF9694000 \SystemRoot\system32\DRIVERS\psched.sys 0xFA0CC000 \SystemRoot\system32\DRIVERS\msgpc.sys 0xFA1EC000 \SystemRoot\system32\DRIVERS\ptilink.sys 0xFA1F4000 \SystemRoot\system32\DRIVERS\raspti.sys 0xF9664000 \SystemRoot\system32\DRIVERS\rdpdr.sys 0xFA0DC000 \SystemRoot\system32\DRIVERS\termdd.sys 0xFA3CA000 \SystemRoot\system32\DRIVERS\swenum.sys 0xF9606000 \SystemRoot\system32\DRIVERS\update.sys 0xF9C8B000 \SystemRoot\system32\DRIVERS\mssmbios.sys 0xFA0EC000 \SystemRoot\System32\Drivers\NDProxy.SYS 0xFA1FC000 \SystemRoot\system32\DRIVERS\flpydisk.sys 0xF9F1C000 \SystemRoot\system32\DRIVERS\usbhub.sys 0xFA3CC000 \SystemRoot\system32\DRIVERS\USBD.SYS 0xFA3D0000 \SystemRoot\System32\Drivers\Fs_Rec.SYS 0xFA4AC000 \SystemRoot\System32\Drivers\Null.SYS 0xFA3D2000 \SystemRoot\System32\Drivers\Beep.SYS 0xFA214000 \SystemRoot\System32\drivers\vga.sys 0xFA3D4000 \SystemRoot\System32\Drivers\mnmdd.SYS 0xFA3D6000 \SystemRoot\System32\DRIVERS\RDPCDD.sys 0xFA21C000 \SystemRoot\System32\Drivers\Msfs.SYS 0xFA224000 \SystemRoot\System32\Drivers\Npfs.SYS 0xFA358000 \SystemRoot\system32\DRIVERS\rasacd.sys 0xEE4EC000 \SystemRoot\system32\DRIVERS\ipsec.sys 0xEE493000 \SystemRoot\system32\DRIVERS\tcpip.sys 0xF9F2C000 \SystemRoot\System32\Drivers\aswTdi.SYS 0xEE46B000 \SystemRoot\system32\DRIVERS\netbt.sys 0xEE449000 \SystemRoot\System32\drivers\afd.sys 0xF9F3C000 \SystemRoot\system32\DRIVERS\netbios.sys 0xEE41E000 \SystemRoot\system32\DRIVERS\rdbss.sys 0xEE386000 \SystemRoot\system32\DRIVERS\mrxsmb.sys 0xF9F4C000 \SystemRoot\System32\Drivers\Fips.SYS 0xEE360000 \SystemRoot\system32\DRIVERS\ipnat.sys 0xF9F5C000 \SystemRoot\system32\DRIVERS\wanarp.sys 0xF97A7000 \SystemRoot\system32\DRIVERS\usb8023.sys 0xFA23C000 \SystemRoot\system32\DRIVERS\RNDISMP.SYS 0xEE339000 \SystemRoot\System32\Drivers\aswSP.SYS 0xFA24C000 \SystemRoot\System32\Drivers\Aavmker4.SYS 0xF9FAC000 \SystemRoot\System32\Drivers\Cdfs.SYS 0xBF800000 \SystemRoot\System32\win32k.sys 0xF95E3000 \SystemRoot\System32\drivers\Dxapi.sys 0xFA274000 \SystemRoot\System32\watchdog.sys 0xBF000000 \SystemRoot\System32\drivers\dxg.sys 0xFA598000 \SystemRoot\System32\drivers\dxgthk.sys 0xBF012000 \SystemRoot\System32\SiSGRV.dll 0xBFFA0000 \SystemRoot\System32\ATMFD.DLL 0xEC24D000 \SystemRoot\System32\Drivers\aswFsBlk.SYS 0xFA20C000 \SystemRoot\system32\DRIVERS\AegisP.sys 0xEC1C9000 \SystemRoot\system32\DRIVERS\ndisuio.sys 0xEC032000 \SystemRoot\System32\Drivers\aswMon2.SYS 0xF9292000 \SystemRoot\system32\drivers\wdmaud.sys 0xF959F000 \SystemRoot\system32\drivers\sysaudio.sys 0xF902F000 \SystemRoot\system32\DRIVERS\mrxdav.sys 0xFA3C0000 \SystemRoot\System32\Drivers\ParVdm.SYS 0xF8E97000 \SystemRoot\system32\DRIVERS\srv.sys 0xF8C9E000 \SystemRoot\System32\Drivers\HTTP.sys 0xFA1B4000 \SystemRoot\System32\Drivers\aswRdr.SYS 0xF8A2F000 \SystemRoot\system32\drivers\kmixer.sys 0x7C900000 \WINDOWS\system32\ntdll.dll Processes (total 26): 0 System Idle Process 4 System 564 C:\WINDOWS\system32\smss.exe 612 csrss.exe 636 C:\WINDOWS\system32\winlogon.exe 680 C:\WINDOWS\system32\services.exe 692 C:\WINDOWS\system32\lsass.exe 860 C:\WINDOWS\system32\svchost.exe 908 svchost.exe 1004 C:\WINDOWS\system32\svchost.exe 1040 C:\WINDOWS\system32\svchost.exe 1120 svchost.exe 1180 svchost.exe 1420 C:\Program Files\Alwil Software\Avast5\AvastSvc.exe 1632 C:\WINDOWS\explorer.exe 1728 C:\Program Files\Alwil Software\Avast5\AvastUI.exe 1744 C:\WINDOWS\system32\ctfmon.exe 1756 C:\Program Files\NETGEAR\WG111v2\WG111v2.exe 212 C:\WINDOWS\system32\spoolsv.exe 260 C:\Program Files\Google\Update\GoogleUpdate.exe 596 svchost.exe 2580 alg.exe 3256 C:\WINDOWS\system32\wscntfy.exe 888 C:\Program Files\Adobe\Reader 9.0\Reader\AcroRd32Info.exe 3508 C:\Documents and Settings\Hills\My Documents\Downloads\MBRCheck.exe 2172 wmiprvse.exe \\.\C: –> \\.\PhysicalDrive0 at offset 0x00000000`00007e00 (NTFS) PhysicalDrive0 Model Number: ST340016A, Rev: 3.19 Size Device Name MBR Status ——————————————– 37 GB \\.\PhysicalDrive0 Windows XP MBR code detected SHA1: DA38B874B7713D1B51CBC449F4EF809B0DEC644A Done! RkU Version: 3.8.388.590, Type LE (SR2) ============================================== OS Name: Windows XP Version 5.1.2600 (Service Pack 3) Number of processors #1 ============================================== >Drivers ============================================== 0x804D7000 C:\WINDOWS\system32\ntoskrnl.exe 2189952 bytes (Microsoft Corporation, NT Kernel & System) 0x804D7000 PnpManager 2189952 bytes 0x804D7000 RAW 2189952 bytes 0x804D7000 WMIxWDM 2189952 bytes 0xBF800000 Win32k 1855488 bytes 0xBF800000 C:\WINDOWS\System32\win32k.sys 1855488 bytes (Microsoft Corporation, Multi-User Win32 Driver) 0xF9D06000 Ntfs.sys 577536 bytes (Microsoft Corporation, NT File System Driver) 0xEE386000 C:\WINDOWS\system32\DRIVERS\mrxsmb.sys 458752 bytes (Microsoft Corporation, Windows NT SMB Minirdr) 0xF9606000 C:\WINDOWS\system32\DRIVERS\update.sys 385024 bytes (Microsoft Corporation, Update Driver) 0xEE493000 C:\WINDOWS\system32\DRIVERS\tcpip.sys 364544 bytes (Microsoft Corporation, TCP/IP Protocol Driver) 0xF8E97000 C:\WINDOWS\system32\DRIVERS\srv.sys 360448 bytes (Microsoft Corporation, Server driver) 0xBF012000 C:\WINDOWS\System32\SiSGRV.dll 339968 bytes (Silicon Integrated Systems Corporation, SiS Compatible Super VGA Driver) 0xBFFA0000 C:\WINDOWS\System32\ATMFD.DLL 290816 bytes (Adobe Systems Incorporated, Windows NT OpenType/Type 1 Font Driver) 0xF8C9E000 C:\WINDOWS\System32\Drivers\HTTP.sys 266240 bytes (Microsoft Corporation, HTTP Protocol Stack) 0xF9664000 C:\WINDOWS\system32\DRIVERS\rdpdr.sys 196608 bytes (Microsoft Corporation, Microsoft RDP Device redirector) 0xF9E5D000 ACPI.sys 188416 bytes (Microsoft Corporation, ACPI Driver for NT) 0xF902F000 C:\WINDOWS\system32\DRIVERS\mrxdav.sys 184320 bytes (Microsoft Corporation, Windows NT WebDav Minirdr) 0xF9CD9000 NDIS.sys 184320 bytes (Microsoft Corporation, NDIS 5.1 wrapper driver) 0xF96E0000 C:\WINDOWS\system32\drivers\sis7012.sys 180224 bytes (Silicon Integrated Systems Corporation, SiS 7012 Audio Device WDM Driver) 0xF977B000 C:\WINDOWS\system32\DRIVERS\sisgrp.sys 180224 bytes (Silicon Integrated Systems Corporation, SiS Compatible Super VGA Driver) 0xF8A2F000 C:\WINDOWS\system32\drivers\kmixer.sys 176128 bytes (Microsoft Corporation, Kernel Mode Audio Mixer) 0xEE41E000 C:\WINDOWS\system32\DRIVERS\rdbss.sys 176128 bytes (Microsoft Corporation, Redirected Drive Buffering SubSystem Driver) 0xEE46B000 C:\WINDOWS\system32\DRIVERS\netbt.sys 163840 bytes (Microsoft Corporation, MBT Transport driver) 0xEE339000 C:\WINDOWS\System32\Drivers\aswSP.SYS 159744 bytes (AVAST Software, avast! self protection module) 0xF9E07000 dmio.sys 155648 bytes (Microsoft Corp., Veritas Software, NT Disk Manager I/O Driver) 0xEE360000 C:\WINDOWS\system32\DRIVERS\ipnat.sys 155648 bytes (Microsoft Corporation, IP Network Address Translator) 0xF96BC000 C:\WINDOWS\system32\drivers\portcls.sys 147456 bytes (Microsoft Corporation, Port Class (Class Driver for Port/Miniport Devices)) 0xF972F000 C:\WINDOWS\system32\DRIVERS\USBPORT.SYS 147456 bytes (Microsoft Corporation, USB 1.1 & 2.0 Port Driver) 0xF970C000 C:\WINDOWS\system32\DRIVERS\ks.sys 143360 bytes (Microsoft Corporation, Kernel CSA Library) 0xEE449000 C:\WINDOWS\System32\drivers\afd.sys 139264 bytes (Microsoft Corporation, Ancillary Function Driver for WinSock) 0x806EE000 ACPI_HAL 131840 bytes 0x806EE000 C:\WINDOWS\system32\hal.dll 131840 bytes (Microsoft Corporation, Hardware Abstraction Layer DLL) 0xF9DCF000 fltmgr.sys 131072 bytes (Microsoft Corporation, Microsoft Filesystem Filter Manager) 0xF9E2D000 ftdisk.sys 126976 bytes (Microsoft Corporation, FT Disk Driver) 0xF9CBF000 Mup.sys 106496 bytes (Microsoft Corporation, Multiple UNC Provider driver) 0xF9DEF000 atapi.sys 98304 bytes (Microsoft Corporation, IDE/ATAPI Port Driver) 0xEC032000 C:\WINDOWS\System32\Drivers\aswMon2.SYS 94208 bytes (AVAST Software, avast! File System Filter Driver for Windows XP) 0xF9DA6000 KSecDD.sys 94208 bytes (Microsoft Corporation, Kernel Security Support Provider Interface) 0xF96A5000 C:\WINDOWS\system32\DRIVERS\ndiswan.sys 94208 bytes (Microsoft Corporation, MS PPP Framing Driver (Strong Encryption)) 0xF9292000 C:\WINDOWS\system32\drivers\wdmaud.sys 86016 bytes (Microsoft Corporation, MMSYSTEM Wave/Midi API mapper) 0xF9753000 C:\WINDOWS\system32\DRIVERS\parport.sys 81920 bytes (Microsoft Corporation, Parallel Port Driver) 0xF9767000 C:\WINDOWS\system32\DRIVERS\VIDEOPRT.SYS 81920 bytes (Microsoft Corporation, Video Port Driver) 0xEE4EC000 C:\WINDOWS\system32\DRIVERS\ipsec.sys 77824 bytes (Microsoft Corporation, IPSec Driver) 0xF9D93000 WudfPf.sys 77824 bytes (Microsoft Corporation, Windows Driver Foundation - User-mode Driver Framework Platform Driver) 0xBF000000 C:\WINDOWS\System32\drivers\dxg.sys 73728 bytes (Microsoft Corporation, DirectX Graphics Driver) 0xF9DBD000 sr.sys 73728 bytes (Microsoft Corporation, System Restore Filesystem Filter Driver) 0xF9E4C000 pci.sys 69632 bytes (Microsoft Corporation, NT Plug and Play PCI Enumerator) 0xF9694000 C:\WINDOWS\system32\DRIVERS\psched.sys 69632 bytes (Microsoft Corporation, MS QoS Packet Scheduler) 0xF9FAC000 C:\WINDOWS\System32\Drivers\Cdfs.SYS 65536 bytes (Microsoft Corporation, CD-ROM File System Driver) 0xFA06C000 C:\WINDOWS\system32\DRIVERS\cdrom.sys 65536 bytes (Microsoft Corporation, SCSI CD-ROM Driver) 0xFA03C000 C:\WINDOWS\system32\DRIVERS\serial.sys 65536 bytes (Microsoft Corporation, Serial Device Driver) 0xFA08C000 C:\WINDOWS\system32\drivers\drmk.sys 61440 bytes (Microsoft Corporation, Microsoft Kernel DRM Descrambler Filter) 0xFA07C000 C:\WINDOWS\system32\DRIVERS\redbook.sys 61440 bytes (Microsoft Corporation, Redbook Audio Filter Driver) 0xF959F000 C:\WINDOWS\system32\drivers\sysaudio.sys 61440 bytes (Microsoft Corporation, System Audio WDM Filter) 0xF9F1C000 C:\WINDOWS\system32\DRIVERS\usbhub.sys 61440 bytes (Microsoft Corporation, Default Hub Driver for USB) 0xF9EEC000 C:\WINDOWS\system32\DRIVERS\CLASSPNP.SYS 53248 bytes (Microsoft Corporation, SCSI Class System Dll) 0xFA04C000 C:\WINDOWS\system32\DRIVERS\i8042prt.sys 53248 bytes (Microsoft Corporation, i8042 Port Driver) 0xFA09C000 C:\WINDOWS\system32\DRIVERS\rasl2tp.sys 53248 bytes (Microsoft Corporation, RAS L2TP mini-port/call-manager driver) 0xF9ECC000 VolSnap.sys 53248 bytes (Microsoft Corporation, Volume Shadow Copy Driver) 0xFA0BC000 C:\WINDOWS\system32\DRIVERS\raspptp.sys 49152 bytes (Microsoft Corporation, Peer-to-Peer Tunneling Protocol) 0xF9F4C000 C:\WINDOWS\System32\Drivers\Fips.SYS 45056 bytes (Microsoft Corporation, FIPS Crypto Driver) 0xFA05C000 C:\WINDOWS\system32\DRIVERS\imapi.sys 45056 bytes (Microsoft Corporation, IMAPI Kernel Driver) 0xF9EBC000 MountMgr.sys 45056 bytes (Microsoft Corporation, Mount Manager) 0xFA0AC000 C:\WINDOWS\system32\DRIVERS\raspppoe.sys 45056 bytes (Microsoft Corporation, RAS PPPoE mini-port/call-manager driver) 0xF9F2C000 C:\WINDOWS\System32\Drivers\aswTdi.SYS 40960 bytes (AVAST Software, avast! TDI Filter Driver) 0xF9EAC000 isapnp.sys 40960 bytes (Microsoft Corporation, PNP ISA Bus Driver) 0xFA0EC000 C:\WINDOWS\System32\Drivers\NDProxy.SYS 40960 bytes (Microsoft Corporation, NDIS Proxy) 0xFA0DC000 C:\WINDOWS\system32\DRIVERS\termdd.sys 40960 bytes (Microsoft Corporation, Terminal Server Driver) 0xF9EDC000 disk.sys 36864 bytes (Microsoft Corporation, PnP Disk Driver) 0xFA02C000 C:\WINDOWS\system32\DRIVERS\intelppm.sys 36864 bytes (Microsoft Corporation, Processor Device Driver) 0xFA0CC000 C:\WINDOWS\system32\DRIVERS\msgpc.sys 36864 bytes (Microsoft Corporation, MS General Packet Classifier) 0xF9F3C000 C:\WINDOWS\system32\DRIVERS\netbios.sys 36864 bytes (Microsoft Corporation, NetBIOS interface driver) 0xEC169000 C:\WINDOWS\System32\Drivers\Normandy.SYS 36864 bytes (RKU Driver) 0xF9F5C000 C:\WINDOWS\system32\DRIVERS\wanarp.sys 36864 bytes (Microsoft Corporation, MS Remote Access and Routing ARP Driver) 0xFA224000 C:\WINDOWS\System32\Drivers\Npfs.SYS 32768 bytes (Microsoft Corporation, NPFS Driver) 0xFA23C000 C:\WINDOWS\system32\DRIVERS\RNDISMP.SYS 32768 bytes (Microsoft Corporation, Remote NDIS Miniport) 0xFA13C000 SISAGPX.sys 32768 bytes (Silicon Integrated Systems Corporation, SiS NT AGP Filter) 0xFA1C4000 C:\WINDOWS\system32\DRIVERS\fdc.sys 28672 bytes (Microsoft Corporation, Floppy Disk Controller Driver) 0xFA12C000 C:\WINDOWS\system32\DRIVERS\PCIIDEX.SYS 28672 bytes (Microsoft Corporation, PCI IDE Bus Driver Extension) 0xFA24C000 C:\WINDOWS\System32\Drivers\Aavmker4.SYS 24576 bytes (AVAST Software, avast! Base Kernel-Mode Device Driver for Windows NT/2000/XP) 0xFA1CC000 C:\WINDOWS\system32\DRIVERS\kbdclass.sys 24576 bytes (Microsoft Corporation, Keyboard Class Driver) 0xFA1D4000 C:\WINDOWS\system32\DRIVERS\mouclass.sys 24576 bytes (Microsoft Corporation, Mouse Class Driver) 0xFA214000 C:\WINDOWS\System32\drivers\vga.sys 24576 bytes (Microsoft Corporation, VGA/Super VGA Video Driver) 0xFA20C000 C:\WINDOWS\system32\DRIVERS\AegisP.sys 20480 bytes (Meetinghouse Data Communications, IEEE 802.1X Protocol Driver) 0xFA1B4000 C:\WINDOWS\System32\Drivers\aswRdr.SYS 20480 bytes (AVAST Software, avast! TDI RDR Driver) 0xFA1FC000 C:\WINDOWS\system32\DRIVERS\flpydisk.sys 20480 bytes (Microsoft Corporation, Floppy Driver) 0xFA21C000 C:\WINDOWS\System32\Drivers\Msfs.SYS 20480 bytes (Microsoft Corporation, Mailslot driver) 0xFA134000 PartMgr.sys 20480 bytes (Microsoft Corporation, Partition Manager) 0xFA1EC000 C:\WINDOWS\system32\DRIVERS\ptilink.sys 20480 bytes (Parallel Technologies, Inc., Parallel Technologies DirectParallel IO Library) 0xFA1F4000 C:\WINDOWS\system32\DRIVERS\raspti.sys 20480 bytes (Microsoft Corporation, PTI DirectParallel® mini-port/call-manager driver) 0xFA1E4000 C:\WINDOWS\system32\DRIVERS\TDI.SYS 20480 bytes (Microsoft Corporation, TDI Wrapper) 0xFA1DC000 C:\WINDOWS\system32\DRIVERS\usbohci.sys 20480 bytes (Microsoft Corporation, OHCI USB Miniport Driver) 0xFA274000 C:\WINDOWS\System32\watchdog.sys 20480 bytes (Microsoft Corporation, Watchdog Driver) 0xF9C8B000 C:\WINDOWS\system32\DRIVERS\mssmbios.sys 16384 bytes (Microsoft Corporation, System Management BIOS Driver) 0xEC1C9000 C:\WINDOWS\system32\DRIVERS\ndisuio.sys 16384 bytes (Microsoft Corporation, NDIS User mode I/O Driver) 0xFA388000 C:\WINDOWS\system32\DRIVERS\serenum.sys 16384 bytes (Microsoft Corporation, Serial Port Enumerator) 0xF97A7000 C:\WINDOWS\system32\DRIVERS\usb8023.sys 16384 bytes (Microsoft Corporation, Remote NDIS USB Driver) 0xEC24D000 C:\WINDOWS\System32\Drivers\aswFsBlk.SYS 12288 bytes (AVAST Software, avast! File System Access Blocking Driver) 0xFA2BC000 C:\WINDOWS\system32\BOOTVID.dll 12288 bytes (Microsoft Corporation, VGA Boot Driver) 0xF95E3000 C:\WINDOWS\System32\drivers\Dxapi.sys 12288 bytes (Microsoft Corporation, DirectX API Driver) 0xFA38C000 C:\WINDOWS\system32\DRIVERS\gameenum.sys 12288 bytes (Microsoft Corporation, Game Port Enumerator) 0xFA39C000 C:\WINDOWS\system32\DRIVERS\ndistapi.sys 12288 bytes (Microsoft Corporation, NDIS 3.0 connection wrapper driver) 0xFA358000 C:\WINDOWS\system32\DRIVERS\rasacd.sys 12288 bytes (Microsoft Corporation, RAS Automatic Connection Driver) 0xFA3D2000 C:\WINDOWS\System32\Drivers\Beep.SYS 8192 bytes (Microsoft Corporation, BEEP Driver) 0xFA3B0000 dmload.sys 8192 bytes (Microsoft Corp., Veritas Software., NT Disk Manager Startup Driver) 0xFA3D0000 C:\WINDOWS\System32\Drivers\Fs_Rec.SYS 8192 bytes (Microsoft Corporation, File System Recognizer Driver) 0xFA3AC000 C:\WINDOWS\system32\KDCOM.DLL 8192 bytes (Microsoft Corporation, Kernel Debugger HW Extension DLL) 0xFA3D4000 C:\WINDOWS\System32\Drivers\mnmdd.SYS 8192 bytes (Microsoft Corporation, Frame buffer simulator) 0xFA3C0000 C:\WINDOWS\System32\Drivers\ParVdm.SYS 8192 bytes (Microsoft Corporation, VDM Parallel Driver) 0xFA3D6000 C:\WINDOWS\System32\DRIVERS\RDPCDD.sys 8192 bytes (Microsoft Corporation, RDP Miniport) 0xFA3CA000 C:\WINDOWS\system32\DRIVERS\swenum.sys 8192 bytes (Microsoft Corporation, Plug and Play Software Device Enumerator) 0xFA3CC000 C:\WINDOWS\system32\DRIVERS\USBD.SYS 8192 bytes (Microsoft Corporation, Universal Serial Bus Driver) 0xFA3AE000 C:\WINDOWS\system32\DRIVERS\WMILIB.SYS 8192 bytes (Microsoft Corporation, WMILIB WMI support library Dll) 0xFA5A2000 C:\WINDOWS\system32\DRIVERS\audstub.sys 4096 bytes (Microsoft Corporation, AudStub Driver) 0xFA598000 C:\WINDOWS\System32\drivers\dxgthk.sys 4096 bytes (Microsoft Corporation, DirectX Graphics Driver Thunk) 0xFA4AC000 C:\WINDOWS\System32\Drivers\Null.SYS 4096 bytes (Microsoft Corporation, NULL Driver) 0xFA474000 pciide.sys 4096 bytes (Microsoft Corporation, Generic PCI IDE Bus Driver) ============================================== >Stealth ==============================================
Please read through the instructions to familarize youself with what to expect when the tool runs.

It is vitally important that combofix is renamed before it has even started to download

Please download ComboFix from Link 1or Link 2 to your Desktop.

**Note: In the event you already have Combofix, this is a new version that I need you to download. It is important that it is saved directly to your desktop**

  • If you are using Firefox, make sure that your download settings are as follows:
    -Tools->Options->Main tab
    -Set to "Always ask me where to Save the files".
  • During the download, before you save it to your desktop, rename Combofix to jgh.exe

  • It is important you rename Combofix during the download, but not after.
  • Please do not rename Combofix to other names, but only to the one indicated.
  • Close any open browsers.
  • Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix

———————————————————–

  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before performing a scan. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
  • Click on this link to see a list of programs that should be disabled. The list is not all inclusive. If yours is not listed and you don't know how to disable it, please ask.

    ———————————————————–

  • Double click on ComboFix.exe (jgh.exe in your case) & follow the prompts.
  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]


Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]

Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.

Notes:

1.Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
3. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.

Please post back with
  • combofix log
How is the computer running?


Thanks
Hey Noodletech,

Here is the log for Combo Fix. Computer is a bit better, but still runs slow for around 15 minutes upon startup, especially when opening mozilla firefox.

Cheers

Free



ComboFix 10-12-18.02 - Hills 20/12/2010 20:21:52.3.1 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.224.85 [GMT 10:00]
Running from: c:\documents and settings\[removed]\Desktop\jgh.exe
AV: avast! Antivirus *Disabled/Updated* {7591DB91-41F0-48A3-B128-1A293FD8233D}
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\Fonts\sserifeg.fon

.
((((((((((((((((((((((((( Files Created from 2010-11-20 to 2010-12-20 )))))))))))))))))))))))))))))))
.

2010-12-17 04:32 . 2010-10-11 14:59 45568 -c—-w- c:\windows\system32\dllcache\wab.exe
2010-12-17 04:20 . 2010-11-02 15:17 40960 -c—-w- c:\windows\system32\dllcache\ndproxy.sys
2010-12-11 05:40 . 2007-12-26 00:47 272128 —-a-w- c:\windows\system32\drivers\wg111v2.sys
2010-12-11 05:40 . 2006-07-27 04:26 36864 —-a-w- c:\windows\system32\RtlGina2.dll
2010-12-11 05:40 . 2007-12-25 01:24 344064 —-a-w- c:\windows\system32\SCMLib.dll
2010-12-11 05:40 . 2005-07-19 18:53 966765 —-a-w- c:\windows\system32\acAuth.dll
2010-12-11 05:40 . 2005-01-25 04:30 143360 —-a-w- c:\windows\system32\IpLib.dll
2010-12-11 05:40 . 2010-12-11 05:40 ——– d—–w- c:\program files\NETGEAR
2010-12-11 05:40 . 2010-12-11 05:40 ——– d–h–w- c:\program files\InstallShield Installation Information
2010-12-11 05:40 . 2010-12-11 05:40 ——– d—–w- c:\documents and settings\Hills\Application Data\InstallShield
2010-12-11 02:34 . 2010-12-11 02:34 21035 —-a-w- c:\windows\system32\drivers\AegisP.sys
2010-12-11 02:33 . 2007-12-18 05:46 266240 —-a-w- c:\windows\system32\WG1v2lib.dll
2010-12-11 02:33 . 2007-04-26 20:00 1069056 —-a-w- c:\windows\system32\libeay32.dll
2010-12-11 01:15 . 2010-12-11 01:15 ——– d—–w- c:\windows\system32\wbem\Repository
2010-12-11 01:14 . 2010-12-11 01:14 ——– d—–w- c:\documents and settings\Administrator\Application Data\GRETECH
2010-12-08 07:21 . 2010-12-08 07:21 ——– d—–w- c:\program files\Conduit
2010-12-07 06:08 . 2010-12-07 06:18 ——– d—–w- c:\documents and settings\Administrator\Local Settings\Application Data\Adobe
2010-12-07 06:07 . 2010-12-07 06:07 ——– d—–w- c:\documents and settings\Administrator\Application Data\OpenOffice.org
2010-12-07 06:04 . 2010-12-07 06:04 ——– d—–w- c:\documents and settings\All Users\Application Data\NOS
2010-12-07 06:04 . 2010-12-07 06:04 ——– d—–w- c:\program files\NOS
2010-12-07 06:01 . 2010-12-07 06:01 ——– d—–w- c:\documents and settings\Administrator\Local Settings\Application Data\Mozilla
2010-11-29 06:55 . 2010-11-29 06:55 0 —-a-w- c:\windows\system32\ConduitEngine.tmp
2010-11-21 12:52 . 2010-11-21 12:52 ——– d—–w- c:\documents and settings\Hills\Application Data\Malwarebytes
2010-11-21 12:52 . 2010-11-21 12:52 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-11-18 18:12 . 2009-07-20 23:30 81920 —-a-w- c:\windows\system32\isign32.dll
2010-11-06 00:26 . 2007-07-27 12:00 916480 —-a-w- c:\windows\system32\wininet.dll
2010-11-06 00:26 . 2007-07-27 12:00 43520 —-a-w- c:\windows\system32\licmgr10.dll
2010-11-06 00:26 . 2007-07-27 12:00 1469440 ——w- c:\windows\system32\inetcpl.cpl
2010-11-03 12:25 . 2007-07-27 12:00 385024 —-a-w- c:\windows\system32\html.iec
2010-11-02 15:17 . 2007-07-27 12:00 40960 —-a-w- c:\windows\system32\drivers\ndproxy.sys
2010-10-28 13:13 . 2007-07-27 12:00 290048 —-a-w- c:\windows\system32\atmfd.dll
2010-10-26 13:25 . 2007-07-27 12:00 1853312 —-a-w- c:\windows\system32\win32k.sys
2010-03-31 05:48 . 2010-03-31 05:47 812344 —-a-w- c:\program files\HJTInstall.exe
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"avast5"="c:\program files\Alwil Software\Avast5\avastUI.exe" [2010-09-07 2838912]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]

c:\documents and settings\Administrator\Start Menu\Programs\Startup\
OpenOffice.org 3.0.lnk - c:\program files\OpenOffice.org 3\program\quickstart.exe [2010-5-20 1195008]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
NETGEAR WG111v2 Smart Wizard.lnk - c:\program files\NETGEAR\WG111v2\WG111v2.exe [2010-12-11 1261568]

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Utility Tray.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Utility Tray.lnk
backup=c:\windows\pss\Utility Tray.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^Hills^Start Menu^Programs^Startup^LimeWire On Startup.lnk]
path=c:\documents and settings\Hills\Start Menu\Programs\Startup\LimeWire On Startup.lnk
backup=c:\windows\pss\LimeWire On Startup.lnkStartup

[HKLM\~\startupfolder\C:^Documents and Settings^Hills^Start Menu^Programs^Startup^OpenOffice.org 3.0.lnk]
path=c:\documents and settings\Hills\Start Menu\Programs\Startup\OpenOffice.org 3.0.lnk
backup=c:\windows\pss\OpenOffice.org 3.0.lnkStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2010-09-20 13:07 932288 —-a-r- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2010-09-22 18:47 35760 —-a-w- c:\program files\Adobe\Reader 9.0\Reader\reader_sl.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msnmsgr]
2009-02-06 08:51 3885408 —-a-w- c:\program files\Windows Live\Messenger\msnmsgr.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SiS Windows KeyHook]
2004-02-26 17:06 241664 —-a-w- c:\windows\system32\Keyhook.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2010-05-14 01:44 248552 —-a-w- c:\program files\Common Files\Java\Java Update\jusched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"Nero BackItUp Scheduler 4.0"=2 (0x2)
"gupdate"=2 (0x2)
"idsvc"=3 (0x3)
"WMPNetworkSvc"=3 (0x3)
"JavaQuickStarterService"=2 (0x2)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Google\\Google Earth\\plugin\\geplugin.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=

R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [20/06/2010 1:29 PM 165584]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [20/06/2010 1:29 PM 17744]
R3 SiS7012;Service for AC'97 Sample Driver (WDM);c:\windows\system32\drivers\sis7012.sys [21/07/2009 9:45 AM 177280]
S0 ncnvyc;ncnvyc;c:\windows\system32\drivers\pqnersy.sys –> c:\windows\system32\drivers\pqnersy.sys [?]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [18/03/2010 1:16 PM 130384]
S3 alcan5ln;SpeedTouch™ USB ADSL RFC1483 Networking Driver (NDIS);c:\windows\system32\drivers\alcan5ln.sys [22/07/2009 10:13 AM 36256]
S3 nosGetPlusHelper;getPlus® Helper 3004;c:\windows\System32\svchost.exe -k nosGetPlusHelper [27/07/2007 10:00 PM 14336]
S3 RTLWUSB;NETGEAR WG111v2 54Mbps Wireless USB 2.0 Adapter NT Driver;c:\windows\system32\drivers\wg111v2.sys [11/12/2010 3:40 PM 272128]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [18/03/2010 1:16 PM 753504]
S4 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [20/07/2010 9:00 PM 136176]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
nosGetPlusHelper REG_MULTI_SZ nosGetPlusHelper
.
Contents of the 'Scheduled Tasks' folder

2010-12-20 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-07-20 10:59]

2010-12-20 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-07-20 10:59]

2010-12-20 c:\windows\Tasks\User_Feed_Synchronization-{10E034B1-B71A-4087-9E07-C1D0A21684BB}.job
- c:\windows\system32\msfeedssync.exe [2007-08-13 18:31]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://au.yahoo.com/
IE: Free YouTube to Mp3 Converter - c:\documents and settings\Hills\Application Data\DVDVideoSoftIEHelpers\youtubetomp3.htm
FF - ProfilePath - c:\documents and settings\Hills\Application Data\Mozilla\Firefox\Profiles\c5apz7ds.default\
FF - prefs.js: browser.search.selectedEngine - Yahoo! Search
FF - prefs.js: browser.startup.homepage - hxxp://ninemsn.com.au
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0019-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0019-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
FF - Ext: Java Quick Starter: [removed] - c:\program files\Java\jre6\lib\deploy\jqs\ff
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - %profile%\extensions\{20a82645-c095-46ed-80e3-08825760534b}
FF - Ext: WOT: {a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7} - %profile%\extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7}
FF - Ext: Calculator: {AA052FD6-366A-4771-A591-0D8DC551585D} - %profile%\extensions\{AA052FD6-366A-4771-A591-0D8DC551585D}
FF - Ext: DVDVideoSoft Menu: {ACAA314B-EEBA-48e4-AD47-84E31C44796C} - %profile%\extensions\{ACAA314B-EEBA-48e4-AD47-84E31C44796C}
FF - Ext: DVDVideoSoftTB Toolbar: {872b5b88-9db5-4310-bdd0-ac189557e5f5} - %profile%\extensions\{872b5b88-9db5-4310-bdd0-ac189557e5f5}
FF - user.js: browser.cache.memory.capacity - 16000
FF - user.js: browser.chrome.favicons - false
FF - user.js: browser.display.show_image_placeholders - true
FF - user.js: browser.turbo.enabled - true
FF - user.js: browser.urlbar.autocomplete.enabled - true
FF - user.js: browser.urlbar.autofill - true
FF - user.js: content.max.tokenizing.time - 3000000
FF - user.js: content.maxtextrun - 4095
FF - user.js: content.notify.backoffcount - 5
FF - user.js: content.notify.interval - 1000000
FF - user.js: content.notify.ontimer - true
FF - user.js: content.switch.threshold - 1000000
FF - user.js: dom.disable_window_status_change - true
FF - user.js: network.http.max-connections - 48
FF - user.js: network.http.max-connections-per-server - 16
FF - user.js: network.http.max-persistent-connections-per-proxy - 16
FF - user.js: network.http.max-persistent-connections-per-server - 8
FF - user.js: network.http.pipelining - true
FF - user.js: network.http.pipelining.firstrequest - true
FF - user.js: network.http.pipelining.maxrequests - 8
FF - user.js: network.http.proxy.pipelining - true
FF - user.js: network.http.request.max-start-delay - 0
FF - user.js: nglayout.initialpaint.delay - 1000
FF - user.js: plugin.expose_full_path - true
FF - user.js: ui.submenuDelay - 0
.
- - - - ORPHANS REMOVED - - - -

MSConfigStartUp-uTorrent - c:\program files\uTorrent\uTorrent.exe



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-12-20 20:30
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10h_ActiveX.exe,-101"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10h_ActiveX.exe"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
Completion time: 2010-12-20 20:34:56
ComboFix-quarantined-files.txt 2010-12-20 10:34
ComboFix2.txt 2010-11-26 10:02

Pre-Run: 6,247,407,616 bytes free
Post-Run: 6,232,838,144 bytes free

- - End Of File - - 008C8A5F46B4C92A7469CA87F905E509
Hi free,

It doesn't look like the issue with your computer being slow is related to malware. Looking at your logs, you only have 224MB of total RAM. This is below the minimum required for Windows XP and is most likely the cause of your computer's sluggishness. A memory upgrade can make a big difference. I would recommend you upgrade to at least 1GB (1024MB) of memory.

You can click here to download the Crucial memory adviser which will tell you how much RAM you currently have and your upgrade options.

Crucial makes top notch quality RAM.

I also suggest you visit our Windows Forum where you can get help for slow computers.

Now let's finish cleaning up your system.

Please do the following:

Follow these steps to uninstall Combofix

  • Click START then RUN
  • Now copy/paste Combofix /uninstall into the runbox and click OK. Note the space between the ..X and the /U, it needs to be there.

[external image: Posted Image]

===================================================

Download TFC to your desktop
  • Open the file and close any other windows.
  • It will close all programs itself when run, make sure to let it run uninterrupted.
  • Click the Start button to begin the process. The program should not take long to finish its job
  • Once its finished it should reboot your machine, if not, do this yourself to ensure a complete clean
THEN

Download Flush Flash from Here and follow the easy to use instructions on the same page

NEXT

Download and run Puran Disc Defragmenter

===================================================

Here are some tips to reduce the potential for spyware infection in the future:

1. Make your Internet Explorer More Secure
  • From within Internet Explorer click on the Tools menu and then click on Options.
  • Click once on the Security tab.
  • Click once on the Internet icon so it becomes highlighted.
  • Click once on the Custom Level button.

    • Change the Download signed ActiveX controls to Prompt.
    • Change the Download unsigned ActiveX controls to Disable.
    • Change the Initialise and script ActiveX controls not marked as safe to Disable.
    • Change the Installation of desktop items to Prompt.
    • Change the Launching programs and files in an IFRAME to Prompt.
    • Change the Navigate sub-frames across different domains to Prompt.
    • When all these settings have been made, click on the OK button.
    • If it prompts you as to whether or not you want to save the settings, press the Yes button.
  • Next press the Apply button and then the OK to exit the Internet Properties page.
2. Update your Anti-Virus Software - I can not overemphasize the need for you to update your Anti-virus application on a regular basis. With the ever increasing number of new variants of malware arriving on the scene daily, you become very susceptible to an attack without updated protection.

3. Make sure you keep your Windows OS current by visiting Windows update regularly to download and install any critical updates and service packs. Without these you are leaving the back door open.

4. Consider a custom hosts file such as MVPS HOSTS. This custom hosts file effectively blocks a wide range of unwanted ads, banners, 3rd party Cookies, 3rd party page counters, web bugs, and many hijackers.
For information on how to download and install, please read this tutorial by WinHelp2002
Note: Be sure to follow the instructions to disable the DNS Client service before installing a custom hosts file.

5. Download and install the free version of WinPatrol. This program protects your computer in a variety of ways and will work well with your existing security software. Have a look at this tutorial to help you get started with the program.

6. Install Spybot - Search and Destroy - Download and install Spybot - Search and Destroy with its TeaTimer option. This will provide real time spyware and hijacker protection on your computer alongside your virus protection. You should scan your computer with the program on a regular basis just as you would with your anti-virus software. A tutorial on installing and using this product can be found here:
Instructions for - Spybot S & D and Ad-aware

7. Finally, I strongly recommend that you read TonyKlein's good advice So how did I get infected in the first place?

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI