Trojan , Malware
23 min read
Those links work just fine for me…. Lets do it this way:blank page
- Please work through the following steps
- Hold down the Windows key (has the Windows symbol on it) and press the "R" key. A Run box will open. Type in Notepad then click on "OK").
- NOTE: Do not Use Wordpad or any other text editor except Notepad or the script will fail.
- Copy and Paste the text in the quotebox below into the open Notepad window:
File::
C:\Documents and Settings\NetworkService\Application Data\Sun\Java\Deployment\cache\6.0\0\694ddfc0-1f825aff
C:\Documents and Settings\NetworkService\Application Data\Sun\Java\Deployment\cache\6.0\37\3f868b65-37241b17
C:\Documents and Settings\NetworkService\Application Data\Sun\Java\Deployment\cache\6.0\40\5c741ce8-4fb2c4be
C:\Documents and Settings\NetworkService\Application Data\Sun\Java\Deployment\cache\6.0\45\16eabf6d-343b3944
C:\Documents and Settings\NetworkService\Application Data\Sun\Java\Deployment\cache\6.0\49\1aaeb971-252807ac
C:\Documents and Settings\NetworkService\Application Data\Sun\Java\Deployment\cache\6.0\61\5ebe80bd-306ad298
C:\Documents and Settings\NetworkService\Application Data\Sun\Java\Deployment\cache\6.0\62\4bd616be-3ad9e232
C:\Documents and Settings\Carly breckenridge\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\count1.val-2419ab08-5fd8212d.zip
C:\Documents and Settings\Carly breckenridge\Application Data\EDD82512F25CA5934581FB38D5EB6E19\enemies-names.txt
C:\Documents and Settings\Carly breckenridge\Application Data\EDD82512F25CA5934581FB38D5EB6E19\local.ini - Save this as "CFScript.txt" (including the quotation marks), change the "Save as type" to "All Files" and save it to your desktop.
- Close any open browsers.
- Disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
- Refering to the picture below, drag CFScript.txt into ComboFix.exe
[external image: Posted Image]
- When finished, it shall produce a log for you at C:\ComboFix.txt which I will require in your next reply.
- exeHelper
- Please download exeHelper by clicking here and save the file (called exeHelper.com) to your desktop.
- Double click on exeHelper.com to run the fix.
- A black window should pop up. Press any key to close once the fix is completed.
- Post the contents of log.txt (it Will be created in the directory where you ran exeHelper.com).
- NOTE: If the window shows a message that says "Error deleting file", please re-run the program before posting a log - and post the two logs together (they will both be in the one file).
Once exeHelper has been run try DDS again. If the link is still not working for you please try one of the links provided below:
http://download.bleepingcomputer.com/sUBs/dds.com
http://www.infospyware.net/sUBs/dds
Please post the ComboFix log and exeHelper log in your next reply along with the DDS logs (if we can get them)
ComboFix 11-01-19.01 - Frank 01/19/2011 18:37:42.3.1 - FAT32x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.479.223 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Frank\Desktop\CFScript.txt
AV: Lavasoft Ad-Watch Live! Anti-Virus *Enabled/Updated* {A1C4F2E0-7FDE-4917-AFAE-013EFC3EDE33}
FILE ::
"c:\documents and settings\Carly breckenridge\Application Data\EDD82512F25CA5934581FB38D5EB6E19\enemies-names.txt"
"c:\documents and settings\Carly breckenridge\Application Data\EDD82512F25CA5934581FB38D5EB6E19\local.ini"
"c:\documents and settings\Carly breckenridge\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\count1.val-2419ab08-5fd8212d.zip"
"c:\documents and settings\NetworkService\Application Data\Sun\Java\Deployment\cache\6.0\0\694ddfc0-1f825aff"
"c:\documents and settings\NetworkService\Application Data\Sun\Java\Deployment\cache\6.0\37\3f868b65-37241b17"
"c:\documents and settings\NetworkService\Application Data\Sun\Java\Deployment\cache\6.0\40\5c741ce8-4fb2c4be"
"c:\documents and settings\NetworkService\Application Data\Sun\Java\Deployment\cache\6.0\45\16eabf6d-343b3944"
"c:\documents and settings\NetworkService\Application Data\Sun\Java\Deployment\cache\6.0\49\1aaeb971-252807ac"
"c:\documents and settings\NetworkService\Application Data\Sun\Java\Deployment\cache\6.0\61\5ebe80bd-306ad298"
"c:\documents and settings\NetworkService\Application Data\Sun\Java\Deployment\cache\6.0\62\4bd616be-3ad9e232"
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\Carly breckenridge\Application Data\EDD82512F25CA5934581FB38D5EB6E19\enemies-names.txt
c:\documents and settings\Carly breckenridge\Application Data\EDD82512F25CA5934581FB38D5EB6E19\local.ini
c:\documents and settings\Carly breckenridge\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\count1.val-2419ab08-5fd8212d.zip
c:\documents and settings\NetworkService\Application Data\Sun\Java\Deployment\cache\6.0\0\694ddfc0-1f825aff
c:\documents and settings\NetworkService\Application Data\Sun\Java\Deployment\cache\6.0\37\3f868b65-37241b17
c:\documents and settings\NetworkService\Application Data\Sun\Java\Deployment\cache\6.0\40\5c741ce8-4fb2c4be
c:\documents and settings\NetworkService\Application Data\Sun\Java\Deployment\cache\6.0\45\16eabf6d-343b3944
c:\documents and settings\NetworkService\Application Data\Sun\Java\Deployment\cache\6.0\49\1aaeb971-252807ac
c:\documents and settings\NetworkService\Application Data\Sun\Java\Deployment\cache\6.0\61\5ebe80bd-306ad298
c:\documents and settings\NetworkService\Application Data\Sun\Java\Deployment\cache\6.0\62\4bd616be-3ad9e232
.
((((((((((((((((((((((((( Files Created from 2010-12-19 to 2011-01-19 )))))))))))))))))))))))))))))))
.
2011-01-19 18:24 . 2011-01-19 18:24 ——– d—–w- c:\program files\ESET
2011-01-19 14:27 . 2011-01-19 14:27 ——– d—–w- c:\documents and settings\Frank\Application Data\Malwarebytes
2011-01-19 14:26 . 2010-12-20 23:09 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-01-19 14:26 . 2011-01-19 14:26 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes
2011-01-19 14:26 . 2011-01-19 14:26 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2011-01-19 14:26 . 2010-12-20 23:08 20952 —-a-w- c:\windows\system32\drivers\mbam.sys
2011-01-18 23:27 . 2011-01-18 23:27 ——– d—–w- C:\FOUND.002
2011-01-13 18:47 . 2010-09-08 12:59 15880 —-a-w- c:\windows\system32\lsdelete.exe
2011-01-13 14:23 . 2010-09-08 12:59 64288 —-a-w- c:\windows\system32\drivers\Lbd.sys
2011-01-13 14:14 . 2011-01-13 14:14 ——– d–h–w- c:\documents and settings\All Users\Application Data\{437292BE-95BD-4B12-B699-6D217A03ACAF}
2011-01-13 14:12 . 2011-01-13 14:12 ——– d—–w- c:\program files\Lavasoft
2011-01-07 19:59 . 2011-01-07 19:59 ——– d—–w- C:\FOUND.001
2011-01-04 02:54 . 2011-01-04 02:54 ——– d—–w- C:\FOUND.000
2011-01-03 21:12 . 2010-11-02 15:17 40960 ——w- c:\windows\system32\dllcache\ndproxy.sys
2011-01-03 21:10 . 2010-10-11 14:59 45568 ——w- c:\windows\system32\dllcache\wab.exe
2010-12-24 14:57 . 2010-12-24 14:57 ——– d—–w- c:\documents and settings\Frank\Application Data\knt3ws3cngrjmwuwiyz1kfkdxvlptbr2
2010-12-22 16:08 . 2010-12-22 16:08 ——– d—–w- c:\documents and settings\Frank\Local Settings\Application Data\Adobe
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-12-18 20:39 . 2010-12-18 20:39 471040 —-a-w- c:\windows\dog2.scr
2010-12-18 20:39 . 2010-12-18 20:39 12288 —-a-w- c:\windows\impborl.dll
2010-11-18 18:12 . 2005-10-15 13:00 81920 —-a-w- c:\windows\system32\isign32.dll
2010-11-09 14:52 . 1980-01-01 05:00 249856 —-a-w- c:\windows\system32\odbc32.dll
2010-11-07 16:31 . 2010-11-07 16:31 98392 —-a-w- c:\windows\system32\drivers\SBREDrv.sys
2010-11-06 00:34 . 1980-01-01 05:00 832512 —-a-w- c:\windows\system32\wininet.dll
2010-11-06 00:34 . 1980-01-01 05:00 78336 —-a-w- c:\windows\system32\ieencode.dll
2010-11-06 00:34 . 1980-01-01 05:00 1830912 —-a-w- c:\windows\system32\inetcpl.cpl
2010-11-06 00:34 . 1980-01-01 05:00 17408 —-a-w- c:\windows\system32\corpol.dll
2010-11-04 21:38 . 2010-11-04 21:39 73728 —-a-w- c:\windows\system32\javacpl.cpl
2010-11-04 21:38 . 2010-11-04 21:39 472808 —-a-w- c:\windows\system32\deployJava1.dll
2010-11-03 12:25 . 1980-01-01 05:00 389120 —-a-w- c:\windows\system32\html.iec
2010-11-02 15:17 . 1980-01-01 05:00 40960 —-a-w- c:\windows\system32\drivers\ndproxy.sys
2010-10-28 13:13 . 1980-01-01 05:00 290048 —-a-w- c:\windows\system32\atmfd.dll
2010-10-26 13:25 . 1980-01-01 06:00 1853312 —-a-w- c:\windows\system32\win32k.sys
2009-04-01 03:47 . 2009-01-19 21:27 324976 —-a-w- c:\program files\mozilla firefox\components\coFFPlgn.dll
.
((((((((((((((((((((((((((((( SnapShot@2011-01-18_21.31.18 )))))))))))))))))))))))))))))))))))))))))
.
+ 2011-01-19 23:29 . 2011-01-19 23:29 16384 c:\windows\Temp\Perflib_Perfdata_8c.dat
+ 2010-11-09 14:52 . 2010-11-09 14:52 249856 c:\windows\system32\dllcache\odbc32.dll
+ 2010-11-09 14:52 . 2010-11-09 14:52 102400 c:\windows\system32\dllcache\msjro.dll
+ 2010-11-09 14:52 . 2010-11-09 14:52 200704 c:\windows\system32\dllcache\msadox.dll
+ 2010-11-09 14:52 . 2010-11-09 14:52 180224 c:\windows\system32\dllcache\msadomd.dll
+ 2010-11-09 14:52 . 2010-11-09 14:52 536576 c:\windows\system32\dllcache\msado15.dll
+ 2010-11-09 14:52 . 2010-11-09 14:52 143360 c:\windows\system32\dllcache\msadco.dll
+ 2011-01-19 16:49 . 2011-01-19 16:49 3141632 c:\windows\Installer\6e8e36.msi
+ 2011-01-19 16:47 . 2011-01-19 16:47 1568768 c:\windows\Installer\6e8e32.msi
+ 2005-10-29 01:02 . 2011-01-19 05:24 37403080 c:\windows\system32\MRT.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2006-09-05 155648]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AGRSMMSG"="AGRSMMSG.exe" [2004-06-29 88363]
"SoundMan"="SOUNDMAN.EXE" [2004-05-14 67072]
"RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2003-10-21 40960]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-05-14 248552]
"Easy-PrintToolBox"="c:\program files\Canon\Easy-PrintToolBox\BJPSMAIN.EXE" [2004-01-14 409600]
"ISUSPM Startup"="c:\program files\Common Files\InstallShield\UpdateService\isuspm.exe" [2005-08-11 249856]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2005-08-11 81920]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2006-09-05 155648]
"PdxRegCl"="c:\program files\Paradox\Programs\PdxRegCl.exe" [2004-06-14 49152]
"QuickFinder Scheduler"="c:\program files\WordPerfect Office X3\Programs\QFSCHD130.EXE" [2005-12-01 77892]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"RunNarrator"="Narrator.exe" [2008-04-14 53760]
c:\documents and settings\Sherry Breckenridge\Start Menu\Programs\Startup\
OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2009-2-26 97680]
Picture Motion Browser Media Check Tool.lnk - c:\program files\Sony\Sony Picture Utility\VolumeWatcher\SPUVolumeWatcher.exe [2007-12-25 344064]
c:\documents and settings\Frank\Start Menu\Programs\Startup\
OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2009-2-26 97680]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2008-4-23 29696]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\WINDOWS\\System32\\usmt\\migwiz.exe"=
"c:\\Program Files\\Messenger\\MSMSGS.EXE"=
"c:\\StubInstaller.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\WINDOWS\\PCHEALTH\\HELPCTR\\BINARIES\\HelpCtr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\Program Files\\Java\\JRE6\\BIN\\java.exe"=
R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [1/13/2011 9:23 AM 64288]
S2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [9/8/2010 7:59 AM 1375992]
S3 Lavasoft Kernexplorer;Lavasoft helper driver;c:\program files\Lavasoft\Ad-Aware\kernexplorer.sys [9/8/2010 7:59 AM 15264]
.
Contents of the 'Scheduled Tasks' folder
2011-01-19 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2010-09-08 14:22]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://sootoday.com/
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
DPF: {A243F6C2-34D2-4549-BCCD-A7BEF759B236} - hxxp://img.funtigo.com/images/uploader/ssiPictureUploader.cab
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-01-19 18:43
Windows 5.1.2600 Service Pack 3 FAT NTAPI
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10k_ActiveX.exe,-101"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10k_ActiveX.exe"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
Completion time: 2011-01-19 18:44:43
ComboFix-quarantined-files.txt 2011-01-19 23:44
ComboFix2.txt 2011-01-19 00:39
ComboFix3.txt 2011-01-18 21:33
Pre-Run: 109,226,459,136 bytes free
Post-Run: 109,483,786,240 bytes free
- - End Of File - - 2C1E3E4AB6774774B2028E6AA628D5CE
Thank you for the dds.txt log.
Me neither. We did'nt touch anything to do with Hotmail.hotmail working now , no idea what happened
That folder is still showing up in your latest log. Please search for it again and delete if found.=============== Created Last 30 ================
2010-12-24 14:57:50 ——– d—–w- c:\docume~1\frank\applic~1\knt3ws3cngrjmwuwiyz1kfkdxvlptbr2
The full path is: c:\documents and settings\Frank\Application Data\knt3ws3cngrjmwuwiyz1kfkdxvlptbr2
I still need to see the DDS attach.txt log that would have been created when you ran DDS.
Please post it in your next reply
IF REQUESTED, ZIP IT UP & ATTACH IT
DDS (Ver_10-12-12.02)
Microsoft Windows XP Home Edition
Boot Device: \Device\HarddiskVolume1
Install Date: 10/15/2005 5:50:31 PM
System Uptime: 1/19/2011 7:50:35 PM (0 hours ago)
Motherboard: Acer | | G74M
Processor: AMD Sempron™ 3000+ | Socket A | 2002/167mhz
==== Disk Partitions =========================
C: is FIXED (FAT32) - 149 GiB total, 101.956 GiB free.
D: is CDROM ()
E: is CDROM ()
G: is Removable
H: is Removable
I: is Removable
J: is Removable
==== Disabled Device Manager Items =============
==== System Restore Points ===================
RP1663: 10/22/2010 8:08:12 AM - System Checkpoint
RP1664: 10/23/2010 8:45:52 AM - System Checkpoint
RP1665: 10/24/2010 9:45:47 AM - System Checkpoint
RP1666: 10/25/2010 10:00:20 AM - System Checkpoint
RP1667: 10/26/2010 11:13:49 AM - System Checkpoint
RP1668: 10/27/2010 12:01:34 PM - System Checkpoint
RP1669: 10/28/2010 12:24:04 PM - System Checkpoint
RP1670: 10/29/2010 1:07:47 PM - System Checkpoint
RP1671: 10/30/2010 1:25:34 PM - System Checkpoint
RP1672: 10/31/2010 2:08:31 PM - System Checkpoint
RP1673: 11/1/2010 3:07:47 PM - System Checkpoint
RP1674: 11/2/2010 3:50:49 PM - System Checkpoint
RP1675: 11/3/2010 4:51:53 PM - System Checkpoint
RP1676: 11/4/2010 3:15:28 PM - Installed Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
RP1677: 11/4/2010 3:15:45 PM - Installed AVG 2011
RP1678: 11/4/2010 3:17:08 PM - Installed AVG 2011
RP1679: 11/4/2010 4:38:29 PM - Installed Java™ 6 Update 22
RP1680: 11/5/2010 4:40:22 PM - System Checkpoint
RP1681: 11/6/2010 4:50:06 PM - System Checkpoint
RP1682: 11/7/2010 11:02:32 AM - Software Distribution Service 3.0
RP1683: 11/8/2010 11:57:36 AM - System Checkpoint
RP1684: 11/9/2010 12:26:52 PM - System Checkpoint
RP1685: 11/10/2010 1:00:22 PM - System Checkpoint
RP1686: 11/11/2010 1:58:21 PM - System Checkpoint
RP1687: 11/12/2010 2:20:08 PM - System Checkpoint
RP1688: 11/13/2010 3:05:55 PM - System Checkpoint
RP1689: 11/14/2010 3:27:50 PM - System Checkpoint
RP1690: 11/15/2010 4:26:44 PM - System Checkpoint
RP1691: 11/16/2010 5:26:43 PM - System Checkpoint
RP1692: 11/17/2010 6:04:35 PM - System Checkpoint
RP1693: 11/18/2010 6:14:13 PM - System Checkpoint
RP1694: 11/19/2010 3:00:24 AM - Software Distribution Service 3.0
RP1695: 11/20/2010 3:59:26 AM - System Checkpoint
RP1696: 11/21/2010 9:15:08 AM - System Checkpoint
RP1697: 11/22/2010 9:56:15 AM - System Checkpoint
RP1698: 11/23/2010 10:56:23 AM - System Checkpoint
RP1699: 11/24/2010 11:50:33 AM - System Checkpoint
RP1700: 11/25/2010 11:57:21 AM - System Checkpoint
RP1701: 11/26/2010 12:57:22 PM - System Checkpoint
RP1702: 11/27/2010 1:46:02 PM - System Checkpoint
RP1703: 11/28/2010 2:26:32 PM - System Checkpoint
RP1704: 11/29/2010 3:26:31 PM - System Checkpoint
RP1705: 11/30/2010 4:26:34 PM - System Checkpoint
RP1706: 12/1/2010 11:09:34 PM - System Checkpoint
RP1707: 12/2/2010 11:45:39 PM - System Checkpoint
RP1708: 12/4/2010 9:00:33 AM - System Checkpoint
RP1709: 12/5/2010 9:08:02 AM - System Checkpoint
RP1710: 12/6/2010 10:08:03 AM - System Checkpoint
RP1711: 12/7/2010 11:08:08 AM - System Checkpoint
RP1712: 12/8/2010 12:08:09 PM - System Checkpoint
RP1713: 12/9/2010 1:03:06 PM - System Checkpoint
RP1714: 12/10/2010 2:00:15 PM - System Checkpoint
RP1715: 12/11/2010 3:06:28 PM - System Checkpoint
RP1716: 12/12/2010 3:18:13 PM - System Checkpoint
RP1717: 12/13/2010 3:49:52 PM - System Checkpoint
RP1718: 12/14/2010 5:34:15 PM - System Checkpoint
RP1719: 12/15/2010 9:15:23 AM - Configured iTunes
RP1720: 12/16/2010 10:17:47 AM - System Checkpoint
RP1721: 12/17/2010 10:28:29 AM - System Checkpoint
RP1722: 12/18/2010 12:02:09 PM - System Checkpoint
RP1723: 12/19/2010 12:17:42 PM - System Checkpoint
RP1724: 12/20/2010 3:16:36 PM - System Checkpoint
RP1725: 12/21/2010 3:17:22 PM - System Checkpoint
RP1726: 12/22/2010 3:55:30 PM - System Checkpoint
RP1727: 12/23/2010 4:27:38 PM - System Checkpoint
RP1728: 12/24/2010 6:31:14 PM - System Checkpoint
RP1729: 12/25/2010 7:12:49 PM - System Checkpoint
RP1730: 12/26/2010 7:42:08 PM - System Checkpoint
RP1731: 12/27/2010 8:07:28 PM - System Checkpoint
RP1732: 12/28/2010 8:40:03 PM - System Checkpoint
RP1733: 12/29/2010 10:35:17 PM - System Checkpoint
RP1734: 12/31/2010 9:08:06 AM - System Checkpoint
RP1735: 1/1/2011 12:10:10 PM - System Checkpoint
RP1736: 1/2/2011 12:27:11 PM - System Checkpoint
RP1737: 1/3/2011 6:14:24 PM - System Checkpoint
RP1738: 1/3/2011 6:16:22 PM - Software Distribution Service 3.0
RP1739: 1/3/2011 11:46:27 PM - Software Distribution Service 3.0
RP1740: 1/5/2011 11:11:02 AM - System Checkpoint
RP1741: 1/6/2011 12:13:34 PM - System Checkpoint
RP1742: 1/7/2011 1:53:20 PM - System Checkpoint
RP1743: 1/8/2011 12:07:06 AM - Software Distribution Service 3.0
RP1744: 1/9/2011 11:27:55 AM - System Checkpoint
RP1745: 1/10/2011 12:42:50 PM - System Checkpoint
RP1746: 1/10/2011 4:29:23 PM - Installed Sony Picture Utility
RP1747: 1/10/2011 4:29:30 PM - Installed Browser
RP1748: 1/10/2011 4:29:57 PM - Installed VolumeWatcher
RP1749: 1/10/2011 4:30:06 PM - Installed InitTool
RP1750: 1/10/2011 4:30:16 PM - Installed Importer
RP1751: 1/10/2011 4:30:25 PM - Installed Announce
RP1752: 1/10/2011 4:30:45 PM - Installed Map View
RP1753: 1/10/2011 4:30:56 PM - Installed DataDiscMaker
RP1754: 1/10/2011 4:31:11 PM - Installed Shared2
RP1755: 1/10/2011 4:32:05 PM - Installed SBS_PXEngine
RP1756: 1/11/2011 7:17:21 PM - System Checkpoint
RP1757: 1/12/2011 7:43:00 PM - System Checkpoint
RP1758: 1/13/2011 8:12:33 PM - System Checkpoint
RP1759: 1/14/2011 8:36:01 PM - System Checkpoint
RP1760: 1/16/2011 11:34:29 AM - System Checkpoint
RP1761: 1/17/2011 12:39:43 PM - System Checkpoint
RP1762: 1/18/2011 1:15:03 PM - System Checkpoint
RP1763: 1/18/2011 3:49:36 PM - Removed AVG 2011
RP1764: 1/18/2011 3:51:26 PM - Removed AVG 2011
RP1765: 1/19/2011 12:23:27 AM - Software Distribution Service 3.0
RP1766: 1/19/2011 11:47:20 AM - Installed AVG 2011
RP1767: 1/19/2011 11:47:53 AM - Installed AVG 2011
RP1768: 1/19/2011 6:25:40 PM - Removed AVG 2011
RP1769: 1/19/2011 6:27:26 PM - Removed AVG 2011
==== Installed Programs ======================
Ad-Aware
Adobe Flash Player 10 ActiveX
Adobe Reader 7.1.0
Agere Systems PCI Soft Modem
Canon iP1600
Canon Utilities Easy-PhotoPrint
Canon Utilities Easy-PrintToolBox
DivX Web Player
Easy-WebPrint
ESET Online Scanner v3
GearDrvs
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
Hotfix for Windows Internet Explorer 7 (KB947864)
Hotfix for Windows XP (KB2158563)
Hotfix for Windows XP (KB2443685)
Hotfix for Windows XP (KB952287)
Hotfix for Windows XP (KB954550-v5)
Hotfix for Windows XP (KB954708)
Hotfix for Windows XP (KB961118)
Hotfix for Windows XP (KB970653-v3)
Hotfix for Windows XP (KB976098-v2)
Hotfix for Windows XP (KB979306)
Hotfix for Windows XP (KB981793)
iPod for Windows 2005-09-23
J2SE Runtime Environment 5.0 Update 3
J2SE Runtime Environment 5.0 Update 4
Java Auto Updater
Java™ 6 Update 22
Junk Mail filter update
Malwarebytes' Anti-Malware
Mavis Beacon Teaches Typing 18
Medical Terminology for Health Professions
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Security Update (KB2416447)
Microsoft .NET Framework 1.1 Security Update (KB979906)
Microsoft .NET Framework 2.0 Service Pack 2
Microsoft .NET Framework 3.0 Service Pack 2
Microsoft .NET Framework 3.5 SP1
Microsoft Application Error Reporting
Microsoft Choice Guard
Microsoft Internationalized Domain Names Mitigation APIs
Microsoft National Language Support Downlevel APIs
Microsoft Office 2007 Service Pack 2 (SP2)
Microsoft Office Excel MUI (English) 2007
Microsoft Office Home and Student 2007
Microsoft Office Live Add-in 1.3
Microsoft Office OneNote MUI (English) 2007
Microsoft Office PowerPoint MUI (English) 2007
Microsoft Office Proof (English) 2007
Microsoft Office Proof (French) 2007
Microsoft Office Proof (Spanish) 2007
Microsoft Office Proofing (English) 2007
Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
Microsoft Office Publisher 2007
Microsoft Office Publisher 2007 Trial
Microsoft Office Publisher MUI (English) 2007
Microsoft Office Shared MUI (English) 2007
Microsoft Office Shared Setup Metadata MUI (English) 2007
Microsoft Office Word MUI (English) 2007
Microsoft Search Enhancement Pack
Microsoft Silverlight
Microsoft Software Update for Web Folders (English) 12
Microsoft SQL Server 2005 Compact Edition [ENU]
Microsoft Sync Framework Runtime Native v1.0 (x86)
Microsoft Sync Framework Services Native v1.0 (x86)
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
MSN
MSN Music Assistant
MSN Toolbar
MSVCRT
MSXML 4.0 SP2 (KB927978)
MSXML 4.0 SP2 (KB936181)
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 (KB973688)
Network Play System (Patching)
NTI Backup NOW! 3
NTI CD & DVD-Maker
NTI CD & DVD-Maker Gold
OpenMG Limited Patch 4.3-05-10-05-01
OpenMG Secure Module 4.3.00
Paradox
PowerDVD
QuickTime
Realtek AC'97 Audio
Security Update for 2007 Microsoft Office System (KB2288621)
Security Update for 2007 Microsoft Office System (KB2288931)
Security Update for 2007 Microsoft Office System (KB2289158)
Security Update for 2007 Microsoft Office System (KB2344875)
Security Update for 2007 Microsoft Office System (KB2345043)
Security Update for 2007 Microsoft Office System (KB969559)
Security Update for 2007 Microsoft Office System (KB976321)
Security Update for Microsoft .NET Framework 3.5 SP1 (KB2416473)
Security Update for Microsoft Office Excel 2007 (KB2345035)
Security Update for Microsoft Office InfoPath 2007 (KB979441)
Security Update for Microsoft Office PowerPoint 2007 (KB982158)
Security Update for Microsoft Office PowerPoint Viewer (KB2413381)
Security Update for Microsoft Office Publisher 2007 (KB2284697)
Security Update for Microsoft Office system 2007 (972581)
Security Update for Microsoft Office system 2007 (KB974234)
Security Update for Microsoft Office Visio Viewer 2007 (KB973709)
Security Update for Microsoft Office Word 2007 (KB2344993)
Security Update for Windows Internet Explorer 7 (KB2183461)
Security Update for Windows Internet Explorer 7 (KB2360131)
Security Update for Windows Internet Explorer 7 (KB2416400)
Security Update for Windows Internet Explorer 7 (KB928090)
Security Update for Windows Internet Explorer 7 (KB929969)
Security Update for Windows Internet Explorer 7 (KB931768)
Security Update for Windows Internet Explorer 7 (KB933566)
Security Update for Windows Internet Explorer 7 (KB937143)
Security Update for Windows Internet Explorer 7 (KB938127)
Security Update for Windows Internet Explorer 7 (KB939653)
Security Update for Windows Internet Explorer 7 (KB942615)
Security Update for Windows Internet Explorer 7 (KB944533)
Security Update for Windows Internet Explorer 7 (KB950759)
Security Update for Windows Internet Explorer 7 (KB953838)
Security Update for Windows Internet Explorer 7 (KB958215)
Security Update for Windows Internet Explorer 7 (KB960714)
Security Update for Windows Internet Explorer 7 (KB961260)
Security Update for Windows Internet Explorer 7 (KB963027)
Security Update for Windows Internet Explorer 7 (KB969897)
Security Update for Windows Internet Explorer 7 (KB972260)
Security Update for Windows Internet Explorer 7 (KB974455)
Security Update for Windows Internet Explorer 7 (KB976325)
Security Update for Windows Internet Explorer 7 (KB978207)
Security Update for Windows Internet Explorer 7 (KB982381)
Security Update for Windows Media Player (KB2378111)
Security Update for Windows Media Player (KB911564)
Security Update for Windows Media Player (KB952069)
Security Update for Windows Media Player (KB954155)
Security Update for Windows Media Player (KB968816)
Security Update for Windows Media Player (KB973540)
Security Update for Windows Media Player (KB975558)
Security Update for Windows Media Player (KB978695)
Security Update for Windows Media Player 10 (KB911565)
Security Update for Windows Media Player 10 (KB917734)
Security Update for Windows Media Player 10 (KB936782)
Security Update for Windows Media Player 6.4 (KB925398)
Security Update for Windows XP (KB2079403)
Security Update for Windows XP (KB2115168)
Security Update for Windows XP (KB2121546)
Security Update for Windows XP (KB2160329)
Security Update for Windows XP (KB2229593)
Security Update for Windows XP (KB2259922)
Security Update for Windows XP (KB2279986)
Security Update for Windows XP (KB2286198)
Security Update for Windows XP (KB2296011)
Security Update for Windows XP (KB2296199)
Security Update for Windows XP (KB2347290)
Security Update for Windows XP (KB2360937)
Security Update for Windows XP (KB2387149)
Security Update for Windows XP (KB2419632)
Security Update for Windows XP (KB2423089)
Security Update for Windows XP (KB2436673)
Security Update for Windows XP (KB2440591)
Security Update for Windows XP (KB2443105)
Security Update for Windows XP (KB923561)
Security Update for Windows XP (KB923689)
Security Update for Windows XP (KB938464-v2)
Security Update for Windows XP (KB938464)
Security Update for Windows XP (KB941569)
Security Update for Windows XP (KB946648)
Security Update for Windows XP (KB950760)
Security Update for Windows XP (KB950762)
Security Update for Windows XP (KB950974)
Security Update for Windows XP (KB951066)
Security Update for Windows XP (KB951376-v2)
Security Update for Windows XP (KB951376)
Security Update for Windows XP (KB951698)
Security Update for Windows XP (KB951748)
Security Update for Windows XP (KB952004)
Security Update for Windows XP (KB952954)
Security Update for Windows XP (KB953839)
Security Update for Windows XP (KB954211)
Security Update for Windows XP (KB954459)
Security Update for Windows XP (KB954600)
Security Update for Windows XP (KB955069)
Security Update for Windows XP (KB956391)
Security Update for Windows XP (KB956572)
Security Update for Windows XP (KB956744)
Security Update for Windows XP (KB956802)
Security Update for Windows XP (KB956803)
Security Update for Windows XP (KB956841)
Security Update for Windows XP (KB956844)
Security Update for Windows XP (KB957095)
Security Update for Windows XP (KB957097)
Security Update for Windows XP (KB958644)
Security Update for Windows XP (KB958687)
Security Update for Windows XP (KB958690)
Security Update for Windows XP (KB958869)
Security Update for Windows XP (KB959426)
Security Update for Windows XP (KB960225)
Security Update for Windows XP (KB960715)
Security Update for Windows XP (KB960803)
Security Update for Windows XP (KB960859)
Security Update for Windows XP (KB961371)
Security Update for Windows XP (KB961373)
Security Update for Windows XP (KB961501)
Security Update for Windows XP (KB968537)
Security Update for Windows XP (KB969059)
Security Update for Windows XP (KB969898)
Security Update for Windows XP (KB969947)
Security Update for Windows XP (KB970238)
Security Update for Windows XP (KB970430)
Security Update for Windows XP (KB971468)
Security Update for Windows XP (KB971486)
Security Update for Windows XP (KB971557)
Security Update for Windows XP (KB971633)
Security Update for Windows XP (KB971657)
Security Update for Windows XP (KB971961)
Security Update for Windows XP (KB972270)
Security Update for Windows XP (KB973346)
Security Update for Windows XP (KB973354)
Security Update for Windows XP (KB973507)
Security Update for Windows XP (KB973525)
Security Update for Windows XP (KB973869)
Security Update for Windows XP (KB973904)
Security Update for Windows XP (KB974112)
Security Update for Windows XP (KB974318)
Security Update for Windows XP (KB974392)
Security Update for Windows XP (KB974571)
Security Update for Windows XP (KB975025)
Security Update for Windows XP (KB975467)
Security Update for Windows XP (KB975560)
Security Update for Windows XP (KB975561)
Security Update for Windows XP (KB975562)
Security Update for Windows XP (KB975713)
Security Update for Windows XP (KB977165)
Security Update for Windows XP (KB977816)
Security Update for Windows XP (KB977914)
Security Update for Windows XP (KB978037)
Security Update for Windows XP (KB978251)
Security Update for Windows XP (KB978262)
Security Update for Windows XP (KB978338)
Security Update for Windows XP (KB978542)
Security Update for Windows XP (KB978601)
Security Update for Windows XP (KB978706)
Security Update for Windows XP (KB979309)
Security Update for Windows XP (KB979482)
Security Update for Windows XP (KB979559)
Security Update for Windows XP (KB979683)
Security Update for Windows XP (KB979687)
Security Update for Windows XP (KB980195)
Security Update for Windows XP (KB980218)
Security Update for Windows XP (KB980232)
Security Update for Windows XP (KB980436)
Security Update for Windows XP (KB981322)
Security Update for Windows XP (KB981349)
Security Update for Windows XP (KB981852)
Security Update for Windows XP (KB981957)
Security Update for Windows XP (KB981997)
Security Update for Windows XP (KB982132)
Security Update for Windows XP (KB982214)
Security Update for Windows XP (KB982665)
Security Update for Windows XP (KB982802)
Segoe UI
SiS 900 PCI Fast Ethernet Adapter Driver
SonicStage 3.3
Sony Picture Utility
Sony PSP Media Manager 1.0a
The Sims Hot Date
Update for 2007 Microsoft Office System (KB967642)
Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
Update for Microsoft Office OneNote 2007 (KB980729)
Update for Windows Internet Explorer 7 (KB976749)
Update for Windows Internet Explorer 7 (KB980182)
Update for Windows XP (KB2141007)
Update for Windows XP (KB2345886)
Update for Windows XP (KB2467659)
Update for Windows XP (KB951072-v2)
Update for Windows XP (KB951978)
Update for Windows XP (KB955759)
Update for Windows XP (KB955839)
Update for Windows XP (KB961503)
Update for Windows XP (KB967715)
Update for Windows XP (KB968389)
Update for Windows XP (KB971737)
Update for Windows XP (KB973687)
Update for Windows XP (KB973815)
Update Manager
Visual C++ 2008 x86 Runtime - (v9.0.30729)
Visual C++ 2008 x86 Runtime - v9.0.30729.01
WebFldrs XP
Windows Genuine Advantage Notifications (KB905474)
Windows Imaging Component
Windows Internet Explorer 7
Windows Live Call
Windows Live Communications Platform
Windows Live Essentials
Windows Live Family Safety
Windows Live Mail
Windows Live Messenger
Windows Live Photo Gallery
Windows Live Sign-in Assistant
Windows Live Sync
Windows Live Toolbar
Windows Live Upload Tool
Windows Live Writer
Windows Media Format Runtime
Windows Media Player 10
Windows XP Service Pack 3
WordPerfect Office X3
Yahoo! Toolbar
==== Event Viewer Messages From Past Week ========
1/18/2011 6:33:21 PM, error: Print [6161] - The document http://forums.whatthetech.com/index.php?sh…6641&pid=70 owned by Frank failed to print on printer Canon iP1600. Data type: NT EMF 1.008. Size of the spool file in bytes: 2490368. Number of bytes printed: 0. Total number of pages in the document: 8. Number of pages printed: 0. Client machine: \\OEM-B2C5BD1FD69. Win32 error code returned by the print processor: 2 (0x2).
1/18/2011 11:57:55 PM, error: Dhcp [1002] - The IP address lease [removed] for the Network Card with network address 00195B37BFEC has been denied by the DHCP server 0.0.0.0 (The DHCP Server sent a DHCPNACK message).
1/16/2011 9:07:47 AM, error: Ftdisk [49] - Configuring the Page file for crash dump failed. Make sure there is a page file on the boot partition and that is large enough to contain all physical memory.
1/16/2011 9:07:47 AM, error: Ftdisk [45] - The system could not sucessfully load the crash dump driver.
==== End Of File ===========================
Thank you for the log.
- Please uninstall your outdated Java
- Click on "Start" then on "Control Panel" and then on "Add or remove programs".
- Click on "remove a program". A list of currently installed programs will be displayed.
- Find the "J2SE Runtime Environment 5.0 Update 3" program, click on it once and then click on the "uninstall" button.
- If you are prompted to re-boot your computer to complete the uninstall please do so.
- Repeat for "J2SE Runtime Environment 5.0 Update 4".
- NOTE: Do not uninstall Java™ 6 Update 22.
- Please update your Java
- To update your Java, Click on "Start" then on "Control Panel" and then on the Java icon (looks like a coffee cup).
- In the window that opens, click on the "Update" tab, and then on "Update Now".
- Your Java should begin to update. Please follow any prompts that you receive.
- Please Uninstall Combofix
- Click on "Start" and then on "Run".
- Now type combofix /uninstall in the run box and click "OK". Please note the space between the "x" and the "/Uninstall", it needs to be there.
Once you have completed the above steps please reinstall AVG and let me know how the machine is running now.
This is the first time you have mentioned spam. It may be possible that your email/IM login credentials have been compromised. Please change all of your e mail/IM passwords immediately using a clean machine.sent out a fresh batch of spam yesterday
Once you have done that lets take another look at your system with the following:
- MalwareBytes AntiMalware
- You should still have MBAM installed.
- Open MBAM and update the program.
- Please perform a Full Scan.
- Post the log created in your next reply.
- ESET
- Please run another ESET scan and post the log created.
Please post the logs in your next reply and let me know if you are experiencing any other symptoms besides the spamming.
Ask AI
AI can make mistakes. Check the cited posts. Archived advice can be out-of-date
Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI