This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Internet very slow

13 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi!
When I go to intenet the pages are loading very slow.I have to wait few minutes to load them and some wont open at all.i scanned with mbam and it found 14 files infected.i removed them but the problem is still here.can you tell me what to do?
thanks
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 14:03, on 2011-01-22
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\Explorer.EXE
C:\WINNT\system32\spoolsv.exe
C:\Program Files\Google\Update\1.2.183.39\GoogleCrashHandler.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe
C:\WINNT\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\WINNT\SYSTEM32\bgsvcgen.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINNT\runservice.exe
C:\NAgent\NSCAGENT.EXE
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\wscntfy.exe
C:\WINNT\system32\wuauclt.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.index.hr/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.tportal.hr
R3 - URLSearchHook: (no name) - {472734EA-242A-422b-ADF8-83D1E48CC825} - (no file)
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.6.5805.1910\swg.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINNT\system32\NeroCheck.exe
O4 - HKLM\..\Run: [REGSHAVE] C:\Program Files\REGSHAVE\REGSHAVE.EXE /AUTORUN
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINNT\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKUS\S-1-5-21-1715567821-448539723-725345543-1005\..\RunOnce: [^SetupICWDesktop] C:\Program Files\Internet Explorer\Connection Wizard\icwconn1.exe /desktop (User 'postgres')
O4 - HKUS\S-1-5-21-1715567821-448539723-725345543-1005\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'postgres')
O4 - HKUS\S-1-5-21-1715567821-448539723-725345543-1005\..\RunOnce: [NeroHomeFirstStart] C:\Program Files\Common Files\Ahead\Lib\NMFirstStart.exe (User 'postgres')
O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [^SetupICWDesktop] C:\Program Files\Internet Explorer\Connection Wizard\icwconn1.exe /desktop (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [^SetupICWDesktop] C:\Program Files\Internet Explorer\Connection Wizard\icwconn1.exe /desktop (User 'Default user')
O8 - Extra context menu item: Add to AMV Convert Tool… - C:\Program Files\MP3 Player Utilities 3.79\AMVConverter\grab.html
O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
O8 - Extra context menu item: Google Sidewiki… - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_E11712C84EA7E12B.dll/cmsidewiki.html
O8 - Extra context menu item: MediaManager tool grab multimedia file - C:\Program Files\MP3 Player Utilities 3.79\MediaManager\grab.html
O9 - Extra button: PokerStars - {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - C:\Program Files\PokerStars\PokerStarsUpdate.exe
O9 - Extra button: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra 'Tools' menuitem: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: PokerNordica - {caf8603b-35e9-4f0f-819d-a509543a1e09} - C:\Documents and Settings\HRVOJE\Start Menu\Programs\PokerNordica\PokerNordica.lnk (HKCU)
O14 - IERESET.INF: START_PAGE_URL=http://www.tportal.hr/
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupd…b?1195914664953
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu…b?1203798672625
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload.adobe.com/pub/shockwave/…ash/swflash.cab
O16 - DPF: {D8089245-3211-40F6-819B-9E5E92CD61A2} (FlashXControl Object) - https://signin3.valueactive.eu/Register/Bra…OCX/flashax.cab
O16 - DPF: {F7EDBBEA-1AD2-4EBF-AA07-D453CC29EE65} (Flash Casino Helper Control) - https://plugins.valueactive.eu/flashax/iefax.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = data.centar
O17 - HKLM\Software\..\Telephony: DomainName = data.centar
O17 - HKLM\System\CCS\Services\Tcpip\..\{9F510D09-BF75-453D-9315-17A4038BF7E7}: NameServer = 195.29.166.116 195.29.149.196
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = data.centar
O17 - HKLM\System\CS3\Services\Tcpip\Parameters: Domain = data.centar
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINNT\System32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINNT\System32\browseui.dll
O23 - Service: B's Recorder GOLD Library General Service (bgsvcgen) - B.H.A Corporation - C:\WINNT\SYSTEM32\bgsvcgen.exe
O23 - Service: getPlus® Helper - NOS Microsystems Ltd. - C:\Program Files\NOS\bin\getPlus_HelperSvc.exe
O23 - Service: Google Update Service (gupdate1c988ae56e2ba5a) (gupdate1c988ae56e2ba5a) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: LicCtrl Service (LicCtrlService) - Unknown owner - C:\WINNT\runservice.exe
O23 - Service: NSC Agent (NSDUAgent) - Symantec Corporation - C:\NAgent\NSCAGENT.EXE
O23 - Service: OracleClientCache80 - Unknown owner - C:\orant\BIN\ONRSD80.EXE
O23 - Service: PostgreSQL Database Server 8.3 (pgsql-8.3) - PostgreSQL Global Development Group - C:\Program Files\PostgreSQL\8.3\bin\pg_ctl.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\PC Tools Security\pctsAuxs.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\PC Tools Security\pctsSvc.exe

–
End of file - 10002 bytes
Hi,

Please do the following:


Please download DDS from either of these links

LINK 1
LINK 2

and save it to your desktop.
  • Disable any script blocking protection
  • Double click dds to run the tool.
  • When done, two DDS.txt's will open.
  • Save both reports to your desktop.
—————————————————
Please include the contents of the following in your next reply:

DDS.txt
Attach.txt.


NEXT


Download GMER Rootkit Scanner from here to your desktop. It will be a randomly named executable.
  • Double click the exe file.
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO, then use the following settings for a more complete scan.

    [external image: Posted Image]
    Click the image to enlarge it
  • In the right panel, you will see several boxes that have been checked. Ensure the following are unchecked
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and attach it in reply.

**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries
DDS (Ver_09-06-26.01) - NTFSx86
Run by [removed] at 14:57:55.37 on 2011-01-22
Internet Explorer: 6.0.2900.2180 BrowserJavaVersion: 1.6.0_10
Microsoft Windows XP Professional 5.1.2600.2.1250.385.1033.18.511.228 [GMT 1:00]


============== Running Processes ===============

C:\WINNT\system32\svchost -k DcomLaunch
svchost.exe
C:\WINNT\System32\svchost.exe -k netsvcs
C:\WINNT\system32\svchost.exe -k WudfServiceGroup
svchost.exe
svchost.exe
C:\WINNT\Explorer.EXE
C:\WINNT\system32\spoolsv.exe
C:\Program Files\Google\Update\1.2.183.39\GoogleCrashHandler.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe
C:\WINNT\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
svchost.exe
C:\WINNT\SYSTEM32\bgsvcgen.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINNT\runservice.exe
C:\NAgent\NSCAGENT.EXE
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\WINNT\System32\svchost.exe -k imgsvc
C:\WINNT\system32\wscntfy.exe
C:\WINNT\system32\wuauclt.exe
C:\Documents and Settings\HRVOJE\Desktop\dds.scr
C:\Documents and Settings\HRVOJE\Desktop\dds.scr

============== Pseudo HJT Report ===============

uStart Page = hxxp://www.index.hr/
uSearch Page = hxxp://www.google.com
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}
uSearch Bar = hxxp://www.google.com/ie
mStart Page = hxxp://www.tportal.hr
uInternet Connection Wizard,ShellNext = iexplore
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
uURLSearchHooks: H - No File
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO: Search Helper: {6ebf7485-159f-4bff-a14f-b9e3aac4465b} - c:\program files\microsoft\search enhancement pack\search helper\SEPsearchhelperie.dll
BHO: Java™ Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre6\bin\ssv.dll
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
BHO: Skype Plug-In: {ae805869-2e5c-4ed4-8f7b-f1f7851a4497} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.6.5805.1910\swg.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: Windows Live Toolbar Helper: {e15a8dc0-8516-42a1-81ea-dc94ec1acf10} - c:\program files\windows live\toolbar\wltcore.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: &Windows Live Toolbar: {21fa44ef-376d-4d53-9b0f-8a89d3229068} - c:\program files\windows live\toolbar\wltcore.dll
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
TB: {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - No File
TB: {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - No File
TB: {D4027C7F-154A-4066-A1AD-4243D8127440} - No File
EB: {32683183-48a0-441b-a342-7c2a440a9478} - No File
uRun: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "c:\program files\common files\ahead\lib\NMBgMonitor.exe"
uRun: [ctfmon.exe] c:\winnt\system32\ctfmon.exe
uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe"
mRun: [Synchronization Manager] mobsync.exe /logon
mRun: [NeroFilterCheck] c:\winnt\system32\NeroCheck.exe
mRun: [REGSHAVE] c:\program files\regshave\REGSHAVE.EXE /AUTORUN
mRun: [TkBellExe] "c:\program files\common files\real\update_ob\realsched.exe" -osboot
mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
dRun: [DWQueuedReporting] "c:\progra~1\common~1\micros~1\dw\dwtrig20.exe" -t
dRunOnce: [^SetupICWDesktop] c:\program files\internet explorer\connection wizard\icwconn1.exe /desktop
dRunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe
IE: Add to AMV Convert Tool… - c:\program files\mp3 player utilities 3.79\amvconverter\grab.html
IE: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
IE: Google Sidewiki… - c:\program files\google\google toolbar\component\GoogleToolbarDynamic_mui_en_E11712C84EA7E12B.dll/cmsidewiki.html
IE: MediaManager tool grab multimedia file - c:\program files\mp3 player utilities 3.79\mediamanager\grab.html
IE: {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - c:\program files\pokerstars\PokerStarsUpdate.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
LSP: c:\program files\common files\pc tools\lsp\PCTLsp.dll
DPF: DirectAnimation Java Classes - file://c:\winnt\java\classes\dajava.cab
DPF: Microsoft XML Parser for Java - file://c:\winnt\java\classes\xmldso.cab
DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://go.microsoft.com/fwlink/?linkid=39204
DPF: {233C1507-6A77-46A4-9443-F871F945D258} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1195914664953
DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1203798672625
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_10-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab
DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} - hxxp://v4.windowsupdate.microsoft.com/CAB/x86/unicode/iuctl.CAB?38411.0485532407
DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_06-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0010-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_10-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_10-windows-i586.cab
DPF: {CEBC955E-58AF-11D2-A30A-00A0C903492B} - hxxp://windowsupdate.microsoft.com/R970/V31Controls/x86/nt5/en/actsetup.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload.adobe.com/pub/shockwave/cabs/flash/swflash.cab
DPF: {D8089245-3211-40F6-819B-9E5E92CD61A2} - hxxps://signin3.valueactive.eu/Register/Branding/olr3313/OCX/flashax.cab
DPF: {F7EDBBEA-1AD2-4EBF-AA07-D453CC29EE65} - hxxps://plugins.valueactive.eu/flashax/iefax.cab
TCP: {9F510D09-BF75-453D-9315-17A4038BF7E7} = 195.29.149.197 195.29.166.117
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
Notify: !SASWinLogon - c:\program files\superantispyware\SASWINLO.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\winnt\system32\WPDShServiceObj.dll
SEH: SABShellExecuteHook Class: {5ae067d3-9afb-48e0-853a-ebb7f4a000da} - c:\program files\superantispyware\SASSEH.DLL

================= FIREFOX ===================

FF - ProfilePath - c:\docume~1\hrvoje\applic~1\mozilla\firefox\profiles\07k032ma.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.jutarnji.hr
FF - plugin: c:\documents and settings\hrvoje\application data\facebook\npfbplugin_1_0_1.dll
FF - plugin: c:\documents and settings\hrvoje\application data\mozilla\firefox\profiles\07k032ma.default\extensions\[removed]\plugins\npTVUAx.dll
FF - plugin: c:\program files\google\google earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\google\google updater\2.4.1487.6512\npCIDetect13.dll
FF - plugin: c:\program files\google\update\1.2.183.39\npGoogleOneClick8.dll
FF - plugin: c:\program files\windows live\photo gallery\NPWLPG.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\winnt\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0010-ABCDEFFEDCBA}

============= SERVICES / DRIVERS ===============

R0 PCTCore;PCTools KDS;c:\winnt\system32\drivers\PCTCore.sys [2011-1-21 239168]
R0 pctDS;PC Tools Data Store;c:\winnt\system32\drivers\pctDS.sys [2011-1-21 338880]
R0 pctEFA;PC Tools Extended File Attributes;c:\winnt\system32\drivers\pctEFA.sys [2011-1-21 656320]
R1 SASDIFSV;SASDIFSV;c:\program files\superantispyware\SASDIFSV.SYS [2009-2-17 9968]
R1 SASKUTIL;SASKUTIL;c:\program files\superantispyware\SASKUTIL.SYS [2009-2-17 55024]
R2 LicCtrlService;LicCtrl Service;c:\winnt\Runservice.exe [2007-4-7 2560]
R2 NSDUAgent;NSC Agent;c:\nagent\NSCAGENT.EXE [2002-4-15 98816]
R2 pgsql-8.3;PostgreSQL Database Server 8.3;c:\program files\postgresql\8.3\bin\pg_ctl.exe [2008-9-19 65536]
R2 SeaPort;SeaPort;c:\program files\microsoft\search enhancement pack\seaport\SeaPort.exe [2009-5-19 240512]
R3 RMSPPPOE;WAN Miniport (PPP over Ethernet Protocol);c:\winnt\system32\drivers\RMSPPPOE.SYS [2002-10-2 31504]
S2 gupdate1c988ae56e2ba5a;Google Update Service (gupdate1c988ae56e2ba5a);c:\program files\google\update\GoogleUpdate.exe [2009-2-6 133104]
S3 Ad-Watch Connect Filter;Ad-Watch Connect Kernel Filter;\??\c:\winnt\system32\drivers\nsdriver.sys –> c:\winnt\system32\drivers\NSDriver.sys [?]
S3 getPlus® Helper;getPlus® Helper;c:\program files\nos\bin\getPlus_HelperSvc.exe [2009-5-4 33176]
S3 OracleClientCache80;OracleClientCache80;c:\orant\bin\ONRSD80.EXE [1998-6-10 95744]
S3 SASENUM;SASENUM;c:\program files\superantispyware\SASENUM.SYS [2009-2-17 7408]
S3 sdAuxService;PC Tools Auxiliary Service;c:\program files\pc tools security\pctsAuxs.exe [2011-1-21 366840]
S3 sdCoreService;PC Tools Security Service;c:\program files\pc tools security\pctsSvc.exe [2011-1-21 1150936]
S3 USB_RNDIS_51;T-Com MAXadsl modem (USB, NDIS);c:\winnt\system32\drivers\usb8023.sys [2003-3-31 12672]
S4 NAV Auto-Protect;NAV Auto-Protect;c:\progra~1\navnt\navapsvc.exe –> c:\progra~1\navnt\navapsvc.exe [?]

============== File Associations ===============

txtfile="c:\winnt\system32\notepad.exe" "%1"

=============== Created Last 30 ================

2011-01-21 17:22 1,264,998 a——- c:\winnt\system32\drivers\Cat.DB
2011-01-21 17:22 656,320 a——- c:\winnt\system32\drivers\pctEFA.sys
2011-01-21 17:22 338,880 a——- c:\winnt\system32\drivers\pctDS.sys
2011-01-21 17:22 249,616 a——- c:\winnt\system32\drivers\pctgntdi.sys
2011-01-21 17:22 239,168 a——- c:\winnt\system32\drivers\PCTCore.sys
2011-01-21 17:22 160,448 a——- c:\winnt\system32\drivers\PCTAppEvent.sys
2011-01-21 17:22 70,536 a——- c:\winnt\system32\drivers\pctplsg.sys
2011-01-21 17:22 –d—– c:\program files\PC Tools Security
2011-01-21 17:22 –d—– c:\docume~1\hrvoje\applic~1\PC Tools
2011-01-21 15:26 –d—– c:\docume~1\alluse~1\applic~1\PC Tools
2011-01-20 23:42 161,792 a——- c:\winnt\SWREG.exe
2011-01-20 23:42 98,816 a——- c:\winnt\sed.exe
2011-01-20 23:42 –d—– C:\ComboFix
2011-01-20 23:42 388,608 a——- c:\winnt\system32\CF22702.exe
2011-01-19 23:00 1,945 a——- c:\winnt\epplauncher.mif
2011-01-18 03:02 –d—– c:\docume~1\alluse~1\applic~1\MFAData
2011-01-17 16:57 388,608 a——- c:\winnt\system32\CF14313.exe
2011-01-17 02:24 –d—– c:\winnt\system32\wbem\Repository
2011-01-17 02:20 –d—– c:\program files\PartyGaming
2011-01-17 02:18 –d—– C:\bwinPoker
2011-01-10 22:39 –d—– c:\docume~1\hrvoje\applic~1\Absolute Poker
2011-01-10 22:17 –d—– c:\docume~1\hrvoje\applic~1\UB
2011-01-07 19:41 –d—– c:\docume~1\hrvoje\applic~1\Mozilla-Cache

==================== Find3M ====================

2010-12-02 16:19 4,096 a——- c:\winnt\d3dx.dat
2010-03-02 14:44 139,152 a——- c:\docume~1\hrvoje\applic~1\PnkBstrK.sys
2009-03-04 10:54 32 a——- c:\docume~1\alluse~1\applic~1\ezsid.dat
2001-07-16 07:32 271 a–sh— c:\program files\desktop.ini
2001-07-16 07:32 21,952 a—h— c:\program files\folder.htt
2009-02-24 14:15 1,393 a–sh— c:\winnt\system32\mmf(2)(2).sys
2009-02-05 15:04 1,393 a–sh— c:\winnt\system32\mmf(3)(2).sys

============= FINISH: 14:59:07.78 ===============



UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT

DDS (Ver_09-06-26.01)

Microsoft Windows XP Professional
Boot Device: \Device\HarddiskVolume1
Install Date: 2007-04-05 12:01:53
System Uptime: 2011-01-22 14:36:31 (0 hours ago)

Motherboard: Hewlett-Packard | | HP System Board
Processor: Intel® Pentium® 4 CPU 1.70GHz | Socket 478 | 1693/100mhz

==== Disk Partitions =========================

A: is Removable
C: is FIXED (NTFS) - 75 GiB total, 11.197 GiB free.
D: is CDROM ()
E: is FIXED (NTFS) - 37 GiB total, 17.769 GiB free.
F: is CDROM ()

==== Disabled Device Manager Items =============

==== System Restore Points ===================

RP1: 2011-01-21 23:23:24 - System Checkpoint
RP2: 2011-01-21 23:57:47 - Software Distribution Service 3.0

==== Installed Programs ======================

ACDSee 32
Acrobat.com
Adobe AIR
Adobe Flash Player 10 ActiveX
Adobe Flash Player 10 Plugin
Adobe Reader 9
Adobe Shockwave Player
Any Video Converter 3.0.3
Apple Software Update
CCleaner
Critical Update for Windows Media Player 11 (KB959772)
DivX Web Player
e-DiagTools LAN Configuration Agent
EZTMusicManager
Facebook Plug-In
Fast Video Upload for Facebook 2.4
FinePixViewer Resource
FinePixViewer Ver.5.2
Folder Size Shell Extension v3.2
FUJIFILM USB Driver
FunPhotor 5.0
Google Earth
Google Toolbar for Internet Explorer
Google Update Helper
Google Updater
Graboid Video 1.65
Heads Up Poker Calculator
Highlight Viewer (Windows Live Toolbar)
HiJackThis
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
Hotfix for Windows Media Format 11 SDK (KB929399)
Hotfix for Windows Media Player 11 (KB939683)
Hotfix for Windows XP (KB915865)
Hotfix for Windows XP (KB926239)
Hotfix for Windows XP (KB952287)
Hotfix for Windows XP (KB954550-v5)
Hotfix for Windows XP (KB954708)
Hotfix for Windows XP (KB961118)
Hotfix for Windows XP (KB970653-v3)
Hotfix for Windows XP (KB976002-v5)
Hotfix for Windows XP (KB976098-v2)
Hotfix for Windows XP (KB979306)
Hotfix for Windows XP (KB981793)
Intel® PRO Ethernet Adapter and Software
J2SE Runtime Environment 5.0 Update 6
Java™ 6 Update 10
Java™ 6 Update 7
K-Lite Codec Pack 2.80 Full
LimeWire 5.5.10
LiveUpdate 2.6 (Symantec Corporation)
Malwarebytes' Anti-Malware
Map Button (Windows Live Toolbar)
Microsoft .NET Framework (English)
Microsoft .NET Framework (English) v1.0.3705
Microsoft .NET Framework 1.0 Hotfix (KB886906)
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Security Update (KB979906)
Microsoft .NET Framework 2.0 Language Pack - DEU
Microsoft .NET Framework 2.0 Service Pack 2
Microsoft .NET Framework 3.0 Service Pack 2
Microsoft .NET Framework 3.5 SP1
Microsoft Application Error Reporting
Microsoft Choice Guard
Microsoft Compression Client Pack 1.0 for Windows XP
Microsoft Data Access Components KB870669
Microsoft Internationalized Domain Names Mitigation APIs
Microsoft Kernel-Mode Driver Framework Feature Pack 1.5
Microsoft National Language Support Downlevel APIs
Microsoft Office 2000 Professional
Microsoft Office PowerPoint Viewer 2007 (English)
Microsoft Search Enhancement Pack
Microsoft Silverlight
Microsoft SQL Server 2005 Compact Edition [ENU]
Microsoft Sync Framework Runtime Native v1.0 (x86)
Microsoft Sync Framework Services Native v1.0 (x86)
Microsoft User-Mode Driver Framework Feature Pack 1.0
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
Mozilla Firefox (3.0.19)
MP3 Player Utilities 3.79
MSVCRT
MSXML 4.0 SP2 (KB936181)
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 (KB973688)
MSXML 6 Service Pack 2 (KB973686)
Nero 7 Demo
Neuro-Programmer Professional 2.3.6
NHL Eastside Hockey Manager 2007
Open Fitness 2.0.0
OpenOffice.org Installer 1.0
PokerNordica
PokerStars
PostgreSQL 8.3
PowerQuest PartitionMagic 7.0
PPP over Ethernet Protocol 0.98
QuickTime
RAW FILE CONVERTER LE
RealPlayer
Reflection for UNIX and Digital 7.00
Rhapsody Player Engine
SAMSUNG CDMA Modem Driver Set
SAMSUNG Mobile USB Modem ^^
SAMSUNG Mobile USB Modem 1.0 Software
SAMSUNG Mobile USB Modem Software
Samsung PC Studio
Security Update for CAPICOM (KB931906)
Security Update for Windows Media Player (KB911564)
Security Update for Windows Media Player (KB952069)
Security Update for Windows Media Player (KB954155)
Security Update for Windows Media Player (KB968816)
Security Update for Windows Media Player (KB973540)
Security Update for Windows Media Player (KB978695)
Security Update for Windows Media Player 11 (KB936782)
Security Update for Windows Media Player 11 (KB954154)
Security Update for Windows Media Player 6.4 (KB925398)
Security Update for Windows Media Player 9 (KB936782)
Security Update for Windows XP (KB2229593)
Security Update for Windows XP (KB890046)
Security Update for Windows XP (KB893756)
Security Update for Windows XP (KB896358)
Security Update for Windows XP (KB896423)
Security Update for Windows XP (KB896428)
Security Update for Windows XP (KB899587)
Security Update for Windows XP (KB899591)
Security Update for Windows XP (KB900725)
Security Update for Windows XP (KB901017)
Security Update for Windows XP (KB901214)
Security Update for Windows XP (KB902400)
Security Update for Windows XP (KB905414)
Security Update for Windows XP (KB905749)
Security Update for Windows XP (KB908519)
Security Update for Windows XP (KB911562)
Security Update for Windows XP (KB911927)
Security Update for Windows XP (KB913580)
Security Update for Windows XP (KB914388)
Security Update for Windows XP (KB914389)
Security Update for Windows XP (KB917344)
Security Update for Windows XP (KB918118)
Security Update for Windows XP (KB918439)
Security Update for Windows XP (KB919007)
Security Update for Windows XP (KB920213)
Security Update for Windows XP (KB920670)
Security Update for Windows XP (KB920683)
Security Update for Windows XP (KB920685)
Security Update for Windows XP (KB922819)
Security Update for Windows XP (KB923191)
Security Update for Windows XP (KB923414)
Security Update for Windows XP (KB923561)
Security Update for Windows XP (KB923810)
Security Update for Windows XP (KB923980)
Security Update for Windows XP (KB924270)
Security Update for Windows XP (KB924496)
Security Update for Windows XP (KB924667)
Security Update for Windows XP (KB925902)
Security Update for Windows XP (KB926255)
Security Update for Windows XP (KB926436)
Security Update for Windows XP (KB927779)
Security Update for Windows XP (KB927802)
Security Update for Windows XP (KB928255)
Security Update for Windows XP (KB928843)
Security Update for Windows XP (KB929123)
Security Update for Windows XP (KB930178)
Security Update for Windows XP (KB931261)
Security Update for Windows XP (KB931784)
Security Update for Windows XP (KB932168)
Security Update for Windows XP (KB933729)
Security Update for Windows XP (KB935839)
Security Update for Windows XP (KB935840)
Security Update for Windows XP (KB936021)
Security Update for Windows XP (KB937894)
Security Update for Windows XP (KB938127)
Security Update for Windows XP (KB938464)
Security Update for Windows XP (KB938829)
Security Update for Windows XP (KB941202)
Security Update for Windows XP (KB941568)
Security Update for Windows XP (KB941569)
Security Update for Windows XP (KB941644)
Security Update for Windows XP (KB943055)
Security Update for Windows XP (KB943460)
Security Update for Windows XP (KB943485)
Security Update for Windows XP (KB944338-v2)
Security Update for Windows XP (KB944533)
Security Update for Windows XP (KB944653)
Security Update for Windows XP (KB946026)
Security Update for Windows XP (KB946648)
Security Update for Windows XP (KB950760)
Security Update for Windows XP (KB950762)
Security Update for Windows XP (KB950974)
Security Update for Windows XP (KB951066)
Security Update for Windows XP (KB951376-v2)
Security Update for Windows XP (KB951698)
Security Update for Windows XP (KB951748)
Security Update for Windows XP (KB952004)
Security Update for Windows XP (KB952954)
Security Update for Windows XP (KB954211)
Security Update for Windows XP (KB954600)
Security Update for Windows XP (KB955069)
Security Update for Windows XP (KB956572)
Security Update for Windows XP (KB956802)
Security Update for Windows XP (KB956803)
Security Update for Windows XP (KB956841)
Security Update for Windows XP (KB956844)
Security Update for Windows XP (KB957097)
Security Update for Windows XP (KB958215)
Security Update for Windows XP (KB958470)
Security Update for Windows XP (KB958644)
Security Update for Windows XP (KB958687)
Security Update for Windows XP (KB958690)
Security Update for Windows XP (KB958869)
Security Update for Windows XP (KB959426)
Security Update for Windows XP (KB960225)
Security Update for Windows XP (KB960714)
Security Update for Windows XP (KB960715)
Security Update for Windows XP (KB960803)
Security Update for Windows XP (KB960859)
Security Update for Windows XP (KB961371)
Security Update for Windows XP (KB961373)
Security Update for Windows XP (KB961501)
Security Update for Windows XP (KB963027)
Security Update for Windows XP (KB968537)
Security Update for Windows XP (KB969059)
Security Update for Windows XP (KB969897)
Security Update for Windows XP (KB969898)
Security Update for Windows XP (KB969947)
Security Update for Windows XP (KB970238)
Security Update for Windows XP (KB970430)
Security Update for Windows XP (KB971032)
Security Update for Windows XP (KB971468)
Security Update for Windows XP (KB971486)
Security Update for Windows XP (KB971557)
Security Update for Windows XP (KB971633)
Security Update for Windows XP (KB971657)
Security Update for Windows XP (KB971961)
Security Update for Windows XP (KB972260)
Security Update for Windows XP (KB972270)
Security Update for Windows XP (KB973346)
Security Update for Windows XP (KB973354)
Security Update for Windows XP (KB973507)
Security Update for Windows XP (KB973525)
Security Update for Windows XP (KB973869)
Security Update for Windows XP (KB973904)
Security Update for Windows XP (KB974112)
Security Update for Windows XP (KB974318)
Security Update for Windows XP (KB974392)
Security Update for Windows XP (KB974455)
Security Update for Windows XP (KB974571)
Security Update for Windows XP (KB975025)
Security Update for Windows XP (KB975467)
Security Update for Windows XP (KB975560)
Security Update for Windows XP (KB975561)
Security Update for Windows XP (KB975562)
Security Update for Windows XP (KB976325)
Security Update for Windows XP (KB977165)
Security Update for Windows XP (KB977816)
Security Update for Windows XP (KB977914)
Security Update for Windows XP (KB978037)
Security Update for Windows XP (KB978251)
Security Update for Windows XP (KB978262)
Security Update for Windows XP (KB978338)
Security Update for Windows XP (KB978542)
Security Update for Windows XP (KB978601)
Security Update for Windows XP (KB978706)
Security Update for Windows XP (KB979309)
Security Update for Windows XP (KB979482)
Security Update for Windows XP (KB979559)
Security Update for Windows XP (KB979683)
Security Update for Windows XP (KB980195)
Security Update for Windows XP (KB980218)
Security Update for Windows XP (KB980232)
Security Update for Windows XP (KB981350)
Security Update for Windows XP (KB982381)
Segoe UI
Skype Toolbars
Skype™ 5.0
Smart Menus (Windows Live Toolbar)
Spelling Dictionaries Support For Adobe Reader 9
Spyware Doctor 8.0
SUPERAntiSpyware Free Edition
Ukloni MAXadsl CD-ROM i upravljačke programe 2.9
Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
Update for Windows XP (KB894391)
Update for Windows XP (KB898461)
Update for Windows XP (KB900485)
Update for Windows XP (KB908531)
Update for Windows XP (KB910437)
Update for Windows XP (KB911280)
Update for Windows XP (KB914882)
Update for Windows XP (KB916595)
Update for Windows XP (KB920872)
Update for Windows XP (KB922582)
Update for Windows XP (KB925720)
Update for Windows XP (KB927891)
Update for Windows XP (KB930916)
Update for Windows XP (KB936357)
Update for Windows XP (KB938828)
Update for Windows XP (KB942763)
Update for Windows XP (KB942840)
Update for Windows XP (KB955759)
Update for Windows XP (KB955839)
Update for Windows XP (KB961503)
Update for Windows XP (KB967715)
Update for Windows XP (KB968389)
Update for Windows XP (KB971737)
Update for Windows XP (KB973687)
Update for Windows XP (KB973815)
Update for Windows XP (KB976749)
Update for Windows XP (KB978207)
Update for Windows XP (KB980182)
VideoLAN VLC media player 0.8.6d
WebFldrs XP
Windows 2000 Application Compatibility Update
Windows Genuine Advantage Notifications (KB905474)
Windows Genuine Advantage Validation Tool (KB892130)
Windows Imaging Component
Windows Installer 3.1 (KB893803)
Windows Live Call
Windows Live Communications Platform
Windows Live Essentials
Windows Live Favorites for Windows Live Toolbar
Windows Live Messenger
Windows Live Photo Gallery
Windows Live Sign-in Assistant
Windows Live Sync
Windows Live Toolbar
Windows Live Toolbar Extension (Windows Live Toolbar)
Windows Live Upload Tool
Windows Media Encoder 7.1
Windows Media Format 11 runtime
Windows Media Player 11
Windows XP Hotfix - KB873339
Windows XP Hotfix - KB885835
Windows XP Hotfix - KB885836
Windows XP Hotfix - KB886185
Windows XP Hotfix - KB887472
Windows XP Hotfix - KB888302
Windows XP Hotfix - KB890859
Windows XP Hotfix - KB891781
Windows XP Service Pack 2
WinRAR archiver
WinZip
X Codec Pack

==== Event Viewer Messages From Past Week ========

2011-01-22 14:34:49, error: Service Control Manager [7034] - The SeaPort service terminated unexpectedly. It has done this 1 time(s).
2011-01-22 14:34:48, error: Service Control Manager [7034] - The NSC Agent service terminated unexpectedly. It has done this 1 time(s).
2011-01-22 14:34:48, error: Service Control Manager [7034] - The LicCtrl Service service terminated unexpectedly. It has done this 1 time(s).
2011-01-22 14:34:48, error: Service Control Manager [7034] - The Java Quick Starter service terminated unexpectedly. It has done this 1 time(s).
2011-01-22 14:34:48, error: Service Control Manager [7034] - The B's Recorder GOLD Library General Service service terminated unexpectedly. It has done this 1 time(s).
2011-01-20 21:44:02, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service netman with arguments "" in order to run the server: {BA126AE5-2166-11D1-B1D0-00805FC1270E}
2011-01-20 21:43:41, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: AFD Fips IPSEC MRxSmb NetBIOS NetBT Processor RasAcd Rdbss SASDIFSV SASKUTIL sptd Tcpip WS2IFSL
2011-01-20 21:43:41, error: Service Control Manager [7001] - The TCP/IP NetBIOS Helper service depends on the AFD Networking Support Environment service which failed to start because of the following error: A device attached to the system is not functioning.
2011-01-20 21:43:41, error: Service Control Manager [7001] - The IPSEC Services service depends on the IPSEC driver service which failed to start because of the following error: A device attached to the system is not functioning.
2011-01-20 21:43:41, error: Service Control Manager [7001] - The DNS Client service depends on the TCP/IP Protocol Driver service which failed to start because of the following error: A device attached to the system is not functioning.
2011-01-20 21:43:41, error: Service Control Manager [7001] - The DHCP Client service depends on the NetBios over Tcpip service which failed to start because of the following error: A device attached to the system is not functioning.
2011-01-20 21:43:38, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service EventSystem with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}
2011-01-20 21:42:49, error: sptd [4] - Driver detected an internal error in its data structures for .
2011-01-20 21:39:28, error: E100B [4] - Adapter Intel® PRO/100 VE Network Connection #2: Adapter Link Down
2011-01-20 19:42:10, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: PCIIde
2011-01-19 23:25:13, error: Microsoft Antimalware [2001] -
2011-01-17 02:35:00, error: Service Control Manager [7022] - The Pokernet service hung on starting.
2011-01-17 02:33:10, error: W32Time [17] - Time Provider NtpClient: An error occurred during DNS lookup of the manually configured peer 'time.windows.com,0x1'. NtpClient will try the DNS lookup again in 15 minutes. The error was: A socket operation was attempted to an unreachable host. (0x80072751)
2011-01-17 01:29:41, error: DCOM [10001] - Unable to start a DCOM Server: {9209B1A6-964A-11D0-9372-00A0C9034910} as /. The error: "%2" Happened while starting this command: C:\WINNT\System32\MDM.EXE -Embedding
2011-01-17 01:12:36, error: DCOM [10001] - Unable to start a DCOM Server: {E367E1A1-E917-11D0-AF5F-00A02448799A} as /. The error: "%2" Happened while starting this command: C:\WINNT\System32\MDM.EXE -Embedding
2011-01-17 01:12:36, error: DCOM [10001] - Unable to start a DCOM Server: {0C0A3666-30C9-11D0-8F20-00805F2CD064} as /. The error: "%2" Happened while starting this command: C:\WINNT\System32\MDM.EXE -Embedding
2011-01-16 11:54:42, error: Service Control Manager [7023] - The Service Eset service terminated with the following error: The specified module could not be found.
2011-01-16 01:19:47, error: Windows Update Agent [20] - Installation Failure: Windows failed to install the following update with error 0x80070643: Security Update for Microsoft .NET Framework, Version 1.0 Service Pack 3 (KB928367).

==== End Of File ===========================
no i cant run it.i tried several times to download it.I downloaded it two times but when i try to enter it it says not a valid Win32 application, and it has only 33.8 KB.And when i am downloading it it wont say how many KB is left to download.
Hi

Please run this program instead:

Scan With RootKitUnHooker

  • Please Download Rootkit Unhooker and save it to your desktop.
  • Now double-click on RKUnhookerLE.exe to run it.
  • Click the Report tab, then click Scan.
  • Check (Tick) Drivers and Stealth
  • Uncheck the rest. then click OK
  • When prompted to Select Disks for Scan, make sure C:\ is checked and click OK
  • Wait till the scanner has finished and then click File > Save Report.
  • Save the report somewhere where you can find it. Click Close.
  • Copy the entire contents of the report and paste it in your next reply.

Note** you may get the following warning, just click OK and continue.

"Rootkit Unhooker has detected a parasite inside itself!
It is recommended to remove parasite, okay?"
RkU Version: 3.8.388.590, Type LE (SR2) ============================================== OS Name: Windows XP Version 5.1.2600 (Service Pack 2) Number of processors #1 ============================================== >Drivers ============================================== 0xBF012000 C:\WINNT\System32\nv4_disp.dll 4276224 bytes (NVIDIA Corporation, NVIDIA Compatible Windows 2000 Display driver, Version 56.73 ) 0x804D7000 C:\WINNT\system32\ntoskrnl.exe 2181376 bytes (Microsoft Corporation, NT Kernel & System) 0x804D7000 PnpManager 2181376 bytes 0x804D7000 RAW 2181376 bytes 0x804D7000 WMIxWDM 2181376 bytes 0xF7C76000 C:\WINNT\System32\DRIVERS\nv4_mini.sys 1900544 bytes (NVIDIA Corporation, NVIDIA Compatible Windows 2000 Miniport Driver, Version 56.73 ) 0xBF800000 Win32k 1851392 bytes 0xBF800000 C:\WINNT\System32\win32k.sys 1851392 bytes (Microsoft Corporation, Multi-User Win32 Driver) 0xF8762000 PCI_PNP1840 995328 bytes 0xF8762000 spfo.sys 995328 bytes 0xF8762000 sptd 995328 bytes 0xF8543000 pctEFA.sys 675840 bytes (PC Tools, PC Tools Extended File Attributes) 0xF848C000 Ntfs.sys 577536 bytes (Microsoft Corporation, NT File System Driver) 0xF1143000 C:\WINNT\System32\DRIVERS\mrxsmb.sys 454656 bytes (Microsoft Corporation, Windows NT SMB Minirdr) 0xF7A77000 C:\WINNT\system32\drivers\smwdm.sys 446464 bytes (Analog Devices, Inc., SoundMAX Integrated Digital Audio ) 0xF3DAB000 C:\WINNT\System32\DRIVERS\update.sys 364544 bytes (Microsoft Corporation, Update Driver) 0xF1269000 C:\WINNT\System32\DRIVERS\tcpip.sys 360448 bytes (Microsoft Corporation, TCP/IP Protocol Driver) 0xF85E8000 pctDS.sys 356352 bytes (PC Tools, PC Tools Data Store) 0xEF55A000 C:\WINNT\System32\DRIVERS\srv.sys 356352 bytes (Microsoft Corporation, Server driver) 0xBFFA0000 C:\WINNT\System32\ATMFD.DLL 286720 bytes (Adobe Systems Incorporated, Windows NT OpenType/Type 1 Font Driver) 0xEED3E000 C:\WINNT\System32\Drivers\HTTP.sys 266240 bytes (Microsoft Corporation, HTTP Protocol Stack) 0xF863F000 PCTCore.sys 249856 bytes (PC Tools, PC Tools KDS Core Driver) 0xF3F97000 C:\WINNT\System32\Drivers\a7pcg3dj.SYS 233472 bytes (Microsoft Corporation, IDE/ATAPI Port Driver) 0xF3E18000 C:\WINNT\System32\DRIVERS\rdpdr.sys 200704 bytes (Microsoft Corporation, Microsoft RDP Device redirector) 0xF871C000 ACPI.sys 188416 bytes (Microsoft Corporation, ACPI Driver for NT) 0xF845F000 NDIS.sys 184320 bytes (Microsoft Corporation, NDIS 5.1 wrapper driver) 0xEF679000 C:\WINNT\System32\DRIVERS\mrxdav.sys 180224 bytes (Microsoft Corporation, Windows NT WebDav Minirdr) 0xED6D1000 C:\WINNT\system32\drivers\kmixer.sys 176128 bytes (Microsoft Corporation, Kernel Mode Audio Mixer) 0xF11B2000 C:\WINNT\System32\DRIVERS\rdbss.sys 176128 bytes (Microsoft Corporation, Redirected Drive Buffering SubSystem Driver) 0xF1241000 C:\WINNT\System32\DRIVERS\netbt.sys 163840 bytes (Microsoft Corporation, MBT Transport driver) 0xF86A6000 dmio.sys 155648 bytes (Microsoft Corp., Veritas Software, NT Disk Manager I/O Driver) 0xF7A53000 C:\WINNT\system32\drivers\portcls.sys 147456 bytes (Microsoft Corporation, Port Class (Class Driver for Port/Miniport Devices)) 0xEF8C8000 C:\WINNT\System32\Drivers\Fastfat.SYS 143360 bytes (Microsoft Corporation, Fast FAT File System Driver) 0xF7B07000 C:\WINNT\System32\DRIVERS\ks.sys 143360 bytes (Microsoft Corporation, Kernel CSA Library) 0xF7AE4000 C:\WINNT\System32\DRIVERS\USBPORT.SYS 143360 bytes (Microsoft Corporation, USB 1.1 & 2.0 Port Driver) 0xF11FE000 C:\WINNT\System32\drivers\afd.sys 139264 bytes (Microsoft Corporation, Ancillary Function Driver for WinSock) 0xF1220000 C:\WINNT\System32\DRIVERS\ipnat.sys 135168 bytes (Microsoft Corporation, IP Network Address Translator) 0xF11DD000 C:\Program Files\SUPERAntiSpyware\SASKUTIL.sys 135168 bytes (SUPERAdBlocker.com and SUPERAntiSpyware.com, SASKUTIL.SYS) 0x806EC000 ACPI_HAL 131968 bytes 0x806EC000 C:\WINNT\system32\hal.dll 131968 bytes (Microsoft Corporation, Hardware Abstraction Layer DLL) 0xF86FC000 fltmgr.sys 131072 bytes (Microsoft Corporation, Microsoft Filesystem Filter Manager) 0xF86CC000 ftdisk.sys 126976 bytes (Microsoft Corporation, FT Disk Driver) 0xF7C44000 C:\WINNT\System32\DRIVERS\e100b325.sys 122880 bytes (Intel Corporation, NDIS 5 driver) 0xF8432000 Mup.sys 110592 bytes (Microsoft Corporation, Multiple UNC Provider driver) 0xF868E000 atapi.sys 98304 bytes (Microsoft Corporation, IDE/ATAPI Port Driver) 0xF112B000 C:\WINNT\System32\Drivers\dump_atapi.sys 98304 bytes 0xF874A000 C:\WINNT\System32\Drivers\SCSIPORT.SYS 98304 bytes (Microsoft Corporation, SCSI Port Driver) 0xF852C000 KSecDD.sys 94208 bytes (Microsoft Corporation, Kernel Security Support Provider Interface) 0xF3F62000 C:\WINNT\System32\DRIVERS\ndiswan.sys 94208 bytes (Microsoft Corporation, MS PPP Framing Driver (Strong Encryption)) 0xEF88B000 C:\WINNT\system32\drivers\wdmaud.sys 86016 bytes (Microsoft Corporation, MMSYSTEM Wave/Midi API mapper) 0xF7C30000 C:\WINNT\System32\DRIVERS\parport.sys 81920 bytes (Microsoft Corporation, Parallel Port Driver) 0xF7C62000 C:\WINNT\System32\DRIVERS\VIDEOPRT.SYS 81920 bytes (Microsoft Corporation, Video Port Driver) 0xF12C1000 C:\WINNT\System32\DRIVERS\ipsec.sys 77824 bytes (Microsoft Corporation, IPSec Driver) 0xF8519000 WudfPf.sys 77824 bytes (Microsoft Corporation, Windows Driver Foundation - User-mode Driver Framework Platform Driver) 0xBF000000 C:\WINNT\System32\drivers\dxg.sys 73728 bytes (Microsoft Corporation, DirectX Graphics Driver) 0xF844D000 sfdrv01.sys 73728 bytes (Protection Technology, StarForce Protection Environment Driver) 0xF867C000 sr.sys 73728 bytes (Microsoft Corporation, System Restore Filesystem Filter Driver) 0xF86EB000 pci.sys 69632 bytes (Microsoft Corporation, NT Plug and Play PCI Enumerator) 0xF60C0000 C:\WINNT\System32\Drivers\Cdfs.SYS 65536 bytes (Microsoft Corporation, CD-ROM File System Driver) 0xF7E66000 C:\WINNT\System32\DRIVERS\serial.sys 65536 bytes (Microsoft Corporation, Serial Device Driver) 0xF8906000 C:\WINNT\system32\drivers\drmk.sys 61440 bytes (Microsoft Corporation, Microsoft Kernel DRM Descrambler Filter) 0xF8A56000 C:\WINNT\System32\DRIVERS\redbook.sys 61440 bytes (Microsoft Corporation, Redbook Audio Filter Driver) 0xF8916000 C:\WINNT\system32\drivers\sysaudio.sys 61440 bytes (Microsoft Corporation, System Audio WDM Filter) 0xF6860000 C:\WINNT\System32\DRIVERS\usbhub.sys 61440 bytes (Microsoft Corporation, Default Hub Driver for USB) 0xF7E46000 C:\WINNT\System32\DRIVERS\cdrom.sys 53248 bytes (Microsoft Corporation, SCSI CD-ROM Driver) 0xF88C6000 C:\WINNT\System32\DRIVERS\CLASSPNP.SYS 53248 bytes (Microsoft Corporation, SCSI Class System Dll) 0xF7E76000 C:\WINNT\System32\DRIVERS\i8042prt.sys 53248 bytes (Microsoft Corporation, i8042 Port Driver) 0xF5D48000 C:\WINNT\System32\DRIVERS\rasl2tp.sys 53248 bytes (Microsoft Corporation, RAS L2TP mini-port/call-manager driver) 0xF88A6000 VolSnap.sys 53248 bytes (Microsoft Corporation, Volume Shadow Copy Driver) 0xF5D28000 C:\WINNT\System32\DRIVERS\raspptp.sys 49152 bytes (Microsoft Corporation, Peer-to-Peer Tunneling Protocol) 0xF88D6000 agp440.sys 45056 bytes (Microsoft Corporation, 440 NT AGP Filter) 0xF7E56000 C:\WINNT\System32\DRIVERS\imapi.sys 45056 bytes (Microsoft Corporation, IMAPI Kernel Driver) 0xF8886000 MountMgr.sys 45056 bytes (Microsoft Corporation, Mount Manager) 0xF5D38000 C:\WINNT\System32\DRIVERS\raspppoe.sys 45056 bytes (Microsoft Corporation, RAS PPPoE mini-port/call-manager driver) 0xF89D6000 C:\WINNT\System32\Drivers\NDProxy.SYS 40960 bytes (Microsoft Corporation, NDIS Proxy) 0xEF4A8000 C:\WINNT\System32\DRIVERS\secdrv.sys 40960 bytes (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K., Macrovision SECURITY Driver) 0xF5CE8000 C:\WINNT\System32\DRIVERS\termdd.sys 40960 bytes (Microsoft Corporation, Terminal Server Driver) 0xF88B6000 disk.sys 36864 bytes (Microsoft Corporation, PnP Disk Driver) 0xF6300000 C:\WINNT\System32\Drivers\Fips.SYS 36864 bytes (Microsoft Corporation, FIPS Crypto Driver) 0xF60B0000 C:\WINNT\System32\DRIVERS\HIDCLASS.SYS 36864 bytes (Microsoft Corporation, Hid Class Library) 0xF8876000 isapnp.sys 36864 bytes (Microsoft Corporation, PNP ISA Bus Driver) 0xF6840000 C:\WINNT\System32\DRIVERS\msgpc.sys 36864 bytes (Microsoft Corporation, MS General Packet Classifier) 0xF6810000 C:\WINNT\System32\DRIVERS\netbios.sys 36864 bytes (Microsoft Corporation, NetBIOS interface driver) 0xEEC6E000 C:\WINNT\System32\Drivers\Normandy.SYS 36864 bytes (RKU Driver) 0xF8A66000 C:\WINNT\System32\DRIVERS\processr.sys 36864 bytes (Microsoft Corporation, Processor Device Driver) 0xF8896000 sfsync02.sys 36864 bytes (Protection Technology, StarForce Protection Synchronization Driver) 0xF60F0000 C:\WINNT\System32\DRIVERS\wanarp.sys 36864 bytes (Microsoft Corporation, MS Remote Access and Routing ARP Driver) 0xF8BC6000 C:\WINNT\System32\Drivers\Npfs.SYS 32768 bytes (Microsoft Corporation, NPFS Driver) 0xF6021000 C:\WINNT\system32\DRIVERS\RMSPPPOE.SYS 32768 bytes (Robert Schlabbach, PPP over Ethernet Protocol NDIS Intermediate Driver) 0xF8B06000 sfhlp02.sys 32768 bytes (Protection Technology, StarForce Protection Helper Driver) 0xF8C4E000 C:\WINNT\System32\DRIVERS\fdc.sys 28672 bytes (Microsoft Corporation, Floppy Disk Controller Driver) 0xF623C000 C:\WINNT\System32\DRIVERS\HIDPARSE.SYS 28672 bytes (Microsoft Corporation, Hid Parsing Library) 0xF8AF6000 C:\WINNT\System32\DRIVERS\PCIIDEX.SYS 28672 bytes (Microsoft Corporation, PCI IDE Bus Driver Extension) 0xF8C46000 C:\WINNT\System32\DRIVERS\kbdclass.sys 24576 bytes (Microsoft Corporation, Keyboard Class Driver) 0xF6029000 C:\WINNT\System32\DRIVERS\mouclass.sys 24576 bytes (Microsoft Corporation, Mouse Class Driver) 0xF8BCE000 C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS 24576 bytes (SUPERAdBlocker.com and SUPERAntiSpyware.com, SASDIFSV.SYS) 0xF8B86000 C:\WINNT\System32\drivers\vga.sys 24576 bytes (Microsoft Corporation, VGA/Super VGA Video Driver) 0xF6D18000 C:\WINNT\System32\DRIVERS\flpydisk.sys 20480 bytes (Microsoft Corporation, Floppy Driver) 0xF8C0E000 C:\WINNT\System32\Drivers\Msfs.SYS 20480 bytes (Microsoft Corporation, Mailslot driver) 0xF8AFE000 PartMgr.sys 20480 bytes (Microsoft Corporation, Partition Manager) 0xF5785000 C:\WINNT\System32\DRIVERS\ptilink.sys 20480 bytes (Parallel Technologies, Inc., Parallel Technologies DirectParallel IO Library) 0xF5775000 C:\WINNT\System32\DRIVERS\raspti.sys 20480 bytes (Microsoft Corporation, PTI DirectParallel® mini-port/call-manager driver) 0xF578D000 C:\WINNT\System32\DRIVERS\TDI.SYS 20480 bytes (Microsoft Corporation, TDI Wrapper) 0xF8C56000 C:\WINNT\System32\DRIVERS\usbuhci.sys 20480 bytes (Microsoft Corporation, UHCI USB Miniport Driver) 0xF8BA6000 C:\WINNT\System32\watchdog.sys 20480 bytes (Microsoft Corporation, Watchdog Driver) 0xF5DE7000 C:\WINNT\System32\DRIVERS\mssmbios.sys 16384 bytes (Microsoft Corporation, System Management BIOS Driver) 0xF8D5A000 C:\WINNT\System32\DRIVERS\serenum.sys 16384 bytes (Microsoft Corporation, Serial Port Enumerator) 0xF8C86000 C:\WINNT\system32\BOOTVID.dll 12288 bytes (Microsoft Corporation, VGA Boot Driver) 0xF23F4000 C:\WINNT\System32\drivers\Dxapi.sys 12288 bytes (Microsoft Corporation, DirectX API Driver) 0xF2CF9000 C:\WINNT\System32\DRIVERS\hidusb.sys 12288 bytes (Microsoft Corporation, USB Miniport Driver for Input Devices) 0xF2CF5000 C:\WINNT\System32\DRIVERS\mouhid.sys 12288 bytes (Microsoft Corporation, HID Mouse Filter Driver) 0xF7681000 C:\WINNT\System32\DRIVERS\ndistapi.sys 12288 bytes (Microsoft Corporation, NDIS 3.0 connection wrapper driver) 0xF358B000 C:\WINNT\System32\DRIVERS\rasacd.sys 12288 bytes (Microsoft Corporation, RAS Automatic Connection Driver) 0xF3583000 C:\WINNT\System32\drivers\ws2ifsl.sys 12288 bytes (Microsoft Corporation, Winsock2 IFS Layer) 0xF8DA0000 C:\WINNT\System32\Drivers\Beep.SYS 8192 bytes (Microsoft Corporation, BEEP Driver) 0xF8D7C000 dmload.sys 8192 bytes (Microsoft Corp., Veritas Software., NT Disk Manager Startup Driver) 0xF8DE2000 C:\WINNT\System32\Drivers\dump_WMILIB.SYS 8192 bytes 0xF8D9E000 C:\WINNT\System32\Drivers\Fs_Rec.SYS 8192 bytes (Microsoft Corporation, File System Recognizer Driver) 0xF8D7A000 intelide.sys 8192 bytes (Microsoft Corporation, Intel PCI IDE Driver) 0xF8D76000 C:\WINNT\system32\KDCOM.DLL 8192 bytes (Microsoft Corporation, Kernel Debugger HW Extension DLL) 0xF8DC4000 C:\WINNT\System32\Drivers\mnmdd.SYS 8192 bytes (Microsoft Corporation, Frame buffer simulator) 0xF8DDE000 C:\WINNT\System32\Drivers\ParVdm.SYS 8192 bytes (Microsoft Corporation, VDM Parallel Driver) 0xF8DE0000 C:\WINNT\System32\DRIVERS\RDPCDD.sys 8192 bytes (Microsoft Corporation, RDP Miniport) 0xF8DF0000 C:\WINNT\System32\DRIVERS\swenum.sys 8192 bytes (Microsoft Corporation, Plug and Play Software Device Enumerator) 0xF8D8E000 C:\WINNT\System32\DRIVERS\USBD.SYS 8192 bytes (Microsoft Corporation, Universal Serial Bus Driver) 0xF8D78000 C:\WINNT\System32\Drivers\WMILIB.SYS 8192 bytes (Microsoft Corporation, WMILIB WMI support library Dll) 0xF8F3C000 C:\WINNT\System32\DRIVERS\audstub.sys 4096 bytes (Microsoft Corporation, AudStub Driver) 0xF3E91000 C:\WINNT\System32\drivers\dxgthk.sys 4096 bytes (Microsoft Corporation, DirectX Graphics Driver Thunk) 0xF8F6B000 C:\WINNT\System32\Drivers\Null.SYS 4096 bytes (Microsoft Corporation, NULL Driver) 0xF8E3E000 pciide.sys 4096 bytes (Microsoft Corporation, Generic PCI IDE Bus Driver) 0xF5765000 C:\WINNT\System32\Drivers\PQNTDrv.SYS 4096 bytes 0xF8F32000 C:\WINNT\system32\drivers\SENSUPGD.SYS 4096 bytes (Sensaura Ltd, Sensaura Upgrade) 0x833DE1F8 unknown_irp_handler 3592 bytes 0x825541F8 unknown_irp_handler 3592 bytes 0x833DF1F8 unknown_irp_handler 3592 bytes 0x82AAA1F8 unknown_irp_handler 3592 bytes 0x833711F8 unknown_irp_handler 3592 bytes 0x82A781F8 unknown_irp_handler 3592 bytes 0x833E01F8 unknown_irp_handler 3592 bytes 0x82A7A1F8 unknown_irp_handler 3592 bytes 0x828371F8 unknown_irp_handler 3592 bytes 0x8281F1F8 unknown_irp_handler 3592 bytes 0x828131F8 unknown_irp_handler 3592 bytes ============================================== >Stealth ============================================== WARNING: File locked for read access [C:\WINNT\system32\drivers\sptd.sys]
Hi,

Please do the following:

Download ComboFix from one of the following locations:
Link 1
Link 2

VERY IMPORTANT !!! Save ComboFix.exe to your Desktop

* IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
  • Double click on ComboFix.exe & follow the prompts.
As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]

  • Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]

  • Click on Yes, to continue scanning for malware.
When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.
Notes:
1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.
right click and delete the one you have on your desktop > download a fresh copy this program is updated daily it isn't something you should keep on your desktop, it is a specialized tool and can cause issues if not deployed correctly
Hi

let's download a recovery console CD manually in case we need it

please do the following:

Please download ARCDC from Artellos.com.
  • Double click ARCDC.exe
  • Follow the dialog until you see 6 options. Please pick: Windows Professional SP2 & SP3
  • You will be prompted with a Terms of Use by Microsoft, please accept.
  • You will see a few dos screens flash by, this is normal.
  • Next you will be able to choose to add extra files. Select the Default Files.
  • The last window will allow you to burn the disk using BurnCDCC
Your ISO is located on your desktop.


NEXT


Continue on with ComboFix without downloading the Recovery Console
Hi, here is the log
ComboFix 11-01-23.07 - HRVOJE 2011-01-24 21:49:39.5.1 - x86
Microsoft Windows XP Professional 5.1.2600.2.1250.385.1033.18.511.243 [GMT 1:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: avast! Antivirus *Disabled/Updated* {7591DB91-41F0-48A3-B128-1A293FD8233D}

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\HRVOJE\My Documents\cc_20110119_205808.reg
C:\popcinfot.dat
c:\winnt\Downloaded Program Files\f3initialsetup1.0.0.15-3.inf
c:\winnt\system32\mswmpdat.tlb
E:\install.exe

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Legacy_EQ2SOFT


((((((((((((((((((((((((( Files Created from 2010-12-24 to 2011-01-24 )))))))))))))))))))))))))))))))
.

2011-01-23 16:15 . 2011-01-13 08:41 294608 —-a-w- c:\winnt\system32\drivers\aswSP.sys
2011-01-23 16:15 . 2011-01-13 08:37 17744 —-a-w- c:\winnt\system32\drivers\aswFsBlk.sys
2011-01-23 16:15 . 2011-01-13 08:40 47440 —-a-w- c:\winnt\system32\drivers\aswTdi.sys
2011-01-23 16:15 . 2011-01-13 08:37 23632 —-a-w- c:\winnt\system32\drivers\aswRdr.sys
2011-01-23 16:15 . 2011-01-13 08:40 100176 —-a-w- c:\winnt\system32\drivers\aswmon2.sys
2011-01-23 16:15 . 2011-01-13 08:39 94544 —-a-w- c:\winnt\system32\drivers\aswmon.sys
2011-01-23 16:15 . 2011-01-13 08:37 29392 —-a-w- c:\winnt\system32\drivers\aavmker4.sys
2011-01-23 16:14 . 2011-01-13 08:47 38848 —-a-w- c:\winnt\avastSS.scr
2011-01-23 16:14 . 2011-01-13 08:47 188216 —-a-w- c:\winnt\system32\aswBoot.exe
2011-01-23 12:09 . 2011-01-23 12:08 86016 –sh–r- c:\winnt\winlogon_22.exe
2011-01-22 16:26 . 2011-01-22 16:25 388608 —-a-w- c:\winnt\system32\CF21748.exe
2011-01-21 16:22 . 2010-07-16 13:59 656320 —-a-w- c:\winnt\system32\drivers\pctEFA.sys
2011-01-21 16:22 . 2010-07-16 13:59 338880 —-a-w- c:\winnt\system32\drivers\pctDS.sys
2011-01-21 16:22 . 2010-11-17 09:19 249616 —-a-w- c:\winnt\system32\drivers\pctgntdi.sys
2011-01-21 16:22 . 2010-11-25 09:53 160448 —-a-w- c:\winnt\system32\drivers\PCTAppEvent.sys
2011-01-21 16:22 . 2010-11-25 09:43 239168 —-a-w- c:\winnt\system32\drivers\PCTCore.sys
2011-01-21 16:22 . 2010-11-25 09:42 70536 —-a-w- c:\winnt\system32\drivers\pctplsg.sys
2011-01-21 16:22 . 2011-01-22 20:44 ——– d—–w- c:\program files\PC Tools Security
2011-01-21 16:22 . 2011-01-21 16:22 ——– d—–w- c:\documents and settings\HRVOJE\Application Data\PC Tools
2011-01-21 14:26 . 2011-01-21 16:22 ——– d—–w- c:\documents and settings\All Users\Application Data\PC Tools
2011-01-20 22:42 . 2011-01-20 22:42 388608 —-a-w- c:\winnt\system32\CF22702.exe
2011-01-20 20:05 . 2011-01-20 20:05 388096 —-a-r- c:\documents and settings\HRVOJE\Application Data\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2011-01-20 13:34 . 2011-01-20 13:34 ——– d—–w- c:\documents and settings\NetworkService\Local Settings\Application Data\PCHealth
2011-01-18 02:02 . 2011-01-20 21:47 ——– d—–w- c:\documents and settings\All Users\Application Data\MFAData
2011-01-17 15:57 . 2011-01-17 15:56 388608 —-a-w- c:\winnt\system32\CF14313.exe
2011-01-17 01:24 . 2011-01-17 01:24 ——– d—–w- c:\winnt\system32\wbem\Repository
2011-01-17 01:20 . 2011-01-17 01:21 ——– d—–w- c:\program files\PartyGaming
2011-01-17 01:18 . 2011-01-17 01:18 ——– d—–w- C:\bwinPoker
2011-01-11 19:53 . 2011-01-11 19:53 ——– d—–w- c:\documents and settings\HRVOJE\Local Settings\Application Data\CPN
2011-01-10 21:39 . 2011-01-17 01:19 ——– d—–w- c:\documents and settings\HRVOJE\Application Data\Absolute Poker
2011-01-10 21:17 . 2011-01-17 01:19 ——– d—–w- c:\documents and settings\HRVOJE\Application Data\UB
2011-01-07 18:41 . 2011-01-07 18:43 ——– d—–w- c:\documents and settings\HRVOJE\Application Data\Mozilla-Cache

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Ahead\lib\NMBgMonitor.exe" [2005-12-16 94208]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-01-15 39408]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Synchronization Manager"="mobsync.exe" [2004-08-03 143360]
"NeroFilterCheck"="c:\winnt\system32\NeroCheck.exe" [2008-12-16 155648]
"REGSHAVE"="c:\program files\REGSHAVE\REGSHAVE.EXE" [2002-02-04 53248]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2008-03-11 185896]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2008-11-28 136600]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672]
"avast5"="c:\program files\Alwil Software\Avast5\avastUI.exe" [2011-01-13 3396624]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-01-31 385024]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-02-25 437160]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"^SetupICWDesktop"="c:\program files\Internet Explorer\Connection Wizard\icwconn1.exe" [2004-08-03 214528]
"tscuninstall"="c:\winnt\system32\tscupgrd.exe" [2004-08-03 44544]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2008-12-22 10:05 356352 —-a-w- c:\program files\SUPERAntiSpyware\SASWINLO.dll

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Logitech SetPoint.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Logitech SetPoint.lnk
backup=c:\winnt\pss\Logitech SetPoint.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
backup=c:\winnt\pss\Microsoft Office.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
2009-10-30 11:57 369200 —-a-w- e:\daemon tools lite\DTLite.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
2010-04-16 21:12 3872080 —-a-w- c:\program files\Windows Live\Messenger\msnmsgr.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2008-01-31 22:13 385024 —-a-w- c:\program files\QuickTime\QTTask.exe

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Nero\\Nero 7\\Nero Home\\NeroHome.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Documents and Settings\\HRVOJE\\Application Data\\PowerChallenge\\PowerSoccer\\PowerSoccer.exe"=
"c:\\Program Files\\Nero\\Nero 7\\Nero ShowTime\\ShowTime.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\Program Files\\Java\\jre1.5.0_06\\bin\\javaw.exe"=
"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=

R0 PCTCore;PCTools KDS;c:\winnt\SYSTEM32\DRIVERS\PCTCore.sys [2011-01-21 239168]
R0 pctDS;PC Tools Data Store;c:\winnt\SYSTEM32\DRIVERS\pctDS.sys [2011-01-21 338880]
R0 pctEFA;PC Tools Extended File Attributes;c:\winnt\SYSTEM32\DRIVERS\pctEFA.sys [2011-01-21 656320]
R0 sptd;sptd;c:\winnt\SYSTEM32\DRIVERS\sptd.sys [2010-01-21 691696]
R1 aswSP;aswSP;c:\winnt\SYSTEM32\DRIVERS\aswSP.sys [2011-01-23 294608]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV.SYS [2009-02-17 9968]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [2009-02-17 55024]
R2 aswFsBlk;aswFsBlk;c:\winnt\SYSTEM32\DRIVERS\aswFsBlk.sys [2011-01-23 17744]
R2 LicCtrlService;LicCtrl Service;c:\winnt\Runservice.exe [2007-04-07 2560]
R2 NSDUAgent;NSC Agent;c:\nagent\NSCAGENT.EXE [2002-04-15 98816]
R3 RMSPPPOE;WAN Miniport (PPP over Ethernet Protocol);c:\winnt\SYSTEM32\DRIVERS\RMSPPPOE.SYS [2002-10-02 31504]
S2 gupdate1c988ae56e2ba5a;Google Update Service (gupdate1c988ae56e2ba5a);c:\program files\Google\Update\GoogleUpdate.exe [2009-02-06 133104]
S3 OracleClientCache80;OracleClientCache80;c:\orant\BIN\ONRSD80.EXE [1998-06-10 95744]
S3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [2009-02-17 7408]
S3 sdAuxService;PC Tools Auxiliary Service;c:\program files\PC Tools Security\pctsAuxs.exe [2011-01-21 366840]
S3 USB_RNDIS_51;T-Com MAXadsl modem (USB, NDIS);c:\winnt\SYSTEM32\DRIVERS\usb8023.sys [2003-03-31 12672]
S4 NAV Auto-Protect;NAV Auto-Protect;c:\progra~1\Navnt\navapsvc.exe –> c:\progra~1\Navnt\navapsvc.exe [?]
.
Contents of the 'Scheduled Tasks' folder

2011-01-21 c:\winnt\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-04-11 15:57]

2011-01-24 c:\winnt\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-02-06 22:57]

2011-01-24 c:\winnt\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-02-06 22:57]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.index.hr/
uSearch Page = hxxp://www.google.com
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}
uSearch Bar = hxxp://www.google.com/ie
mDefault_Search_URL = hxxp://www.google.com/ie
mStart Page = hxxp://www.tportal.hr
uInternet Connection Wizard,ShellNext = iexplore
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
mSearchAssistant = hxxp://www.google.com/ie
IE: Add to AMV Convert Tool… - c:\program files\MP3 Player Utilities 3.79\AMVConverter\grab.html
IE: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
IE: Google Sidewiki… - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_E11712C84EA7E12B.dll/cmsidewiki.html
IE: MediaManager tool grab multimedia file - c:\program files\MP3 Player Utilities 3.79\MediaManager\grab.html
LSP: c:\program files\Common Files\PC Tools\Lsp\PCTLsp.dll
DPF: DirectAnimation Java Classes - file://c:\winnt\Java\classes\dajava.cab
DPF: Microsoft XML Parser for Java - file://c:\winnt\Java\classes\xmldso.cab
FF - ProfilePath - c:\documents and settings\HRVOJE\Application Data\Mozilla\Firefox\Profiles\07k032ma.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.jutarnji.hr
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0010-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0010-ABCDEFFEDCBA}
FF - Ext: TVU Web Player: [removed] - %profile%\extensions\[removed]
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - %profile%\extensions\{20a82645-c095-46ed-80e3-08825760534b}
FF - Ext: Adobe DLM (powered by getPlus®): {CF40ACC5-E1BB-4aff-AC72-04C2F616BCA7} - %profile%\extensions\{CF40ACC5-E1BB-4aff-AC72-04C2F616BCA7}
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\winnt\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
.
- - - - ORPHANS REMOVED - - - -

WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-01-24 22:14
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_USERS\S-1-5-21-1715567821-448539723-725345543-1003\RemoteAccess\Profile\x *]
"EnableAutodisconnect"=dword:00000001
"EnableExitDisconnect"=dword:00000001
"DisconnectIdleTime"=dword:00000014
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(540)
c:\program files\SUPERAntiSpyware\SASWINLO.dll

- - - - - - - > 'lsass.exe'(596)
c:\program files\Common Files\PC Tools\Lsp\PCTLsp.dll

- - - - - - - > 'explorer.exe'(3364)
c:\winnt\system32\WPDShServiceObj.dll
c:\winnt\system32\PortableDeviceTypes.dll
c:\winnt\system32\PortableDeviceApi.dll
.
———————— Other Running Processes ————————
.
c:\program files\Alwil Software\Avast5\AvastSvc.exe
c:\winnt\SYSTEM32\bgsvcgen.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
c:\winnt\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2011-01-24 22:27:33 - machine was rebooted
ComboFix-quarantined-files.txt 2011-01-24 21:27
ComboFix2.txt 2009-02-25 22:12
ComboFix3.txt 2009-02-25 19:59

Pre-Run: 11,780,988,928 bytes free
Post-Run: 11,728,908,288 bytes free

- - End Of File - - 1259666A31C041A9458069DE3D4BD2DD
Hi

Please do the following:


Please go to Virus Total
  • Copy paste the following full path into the empty box under 'Upload a file'

    c:\winnt\winlogon_22.exe

  • Click 'Send File'
  • If a pop-up appears saying the file has been scanned already, please select ReScan
Copy/paste the results into Notepad and save it to your desktop. Please post the results in your next reply.
Antivirus Version Last Update Result
AhnLab-V3 2011.01.18.00 2011.01.17 -
AntiVir 7.11.1.227 2011.01.24 -
Antiy-AVL 2.0.3.7 2011.01.18 -
Avast 4.8.1351.0 2011.01.24 Win32:Trojan-gen
Avast5 5.0.677.0 2011.01.24 Win32:Trojan-gen
AVG 10.0.0.1190 2011.01.24 -
BitDefender 7.2 2011.01.24 -
CAT-QuickHeal 11.00 2011.01.24 -
ClamAV 0.96.4.0 2011.01.24 -
Commtouch 5.2.11.5 2011.01.24 -
DrWeb 5.0.2.03300 2011.01.24 -
Emsisoft 5.1.0.1 2011.01.24 -
eSafe 7.0.17.0 2011.01.23 -
eTrust-Vet 36.1.8115 2011.01.21 -
F-Prot 4.6.2.117 2011.01.23 -
F-Secure 9.0.16160.0 2011.01.24 -
Fortinet 4.2.254.0 2011.01.24 -
GData 21 2011.01.24 Win32:Trojan-gen
Ikarus T3.1.1.97.0 2011.01.24 -
Jiangmin 13.0.900 2011.01.24 -
K7AntiVirus 9.77.3618 2011.01.22 -
Kaspersky 7.0.0.125 2011.01.24 -
McAfee 5.400.0.1158 2011.01.24 -
McAfee-GW-Edition 2010.1C 2011.01.24 -
Microsoft 1.6502 2011.01.24 -
NOD32 5812 2011.01.24 a variant of Win32/Injector.EKW
Norman 6.06.12 2011.01.24 -
nProtect 2011-01-18.01 2011.01.18 -
Panda 10.0.2.7 2011.01.24 -
PCTools 7.0.3.5 2011.01.23 -
Prevx 3.0 2011.01.24 Medium Risk Malware
Rising 23.42.00.06 2011.01.24 -
Sophos 4.61.0 2011.01.24 -
SUPERAntiSpyware 4.40.0.1006 2011.01.24 -
Symantec 20101.3.0.103 2011.01.24 -
TheHacker 6.7.0.1.119 2011.01.24 -
TrendMicro 9.120.0.1004 2011.01.24 -
TrendMicro-HouseCall 9.120.0.1004 2011.01.24 -
VBA32 3.12.14.3 2011.01.24 -
VIPRE 8179 2011.01.24 -
ViRobot 2011.1.24.4272 2011.01.24 -
VirusBuster 13.6.161.0 2011.01.24 -
Additional information
Show all
MD5 : e5618a936533a012e3802391b481ce43
SHA1 : 09b625f9bc9e43a748a155c1285c1946fc1f589e
SHA256: ab3ad005d8ea91c550a7ad159090898110d8bbf9d8610653a67f69303a0ffd7e
ssdeep: 768:tbLUqyxzFNoeOFERwMbV8cT+msJspGAGZmApOZp9E31e/raK:xU9hoeHWklqibTE31e/
File size : 86016 bytes
First seen: 2011-01-24 02:35:40
Last seen : 2011-01-24 22:50:55
TrID:
Win32 Executable MS Visual C++ (generic) (65.2%)
Win32 Executable Generic (14.7%)
Win32 Dynamic Link Library (generic) (13.1%)
Generic Win/DOS Executable (3.4%)
DOS Executable Generic (3.4%)
sigcheck:
publisher….: n/a
copyright….: n/a
product……: n/a
description..: n/a
original name: n/a
internal name: n/a
file version.: n/a
comments…..: n/a
signers……: -
signing date.: -
verified…..: Unsigned
PEiD: Armadillo v1.71
PEInfo: PE structure information

[[ basic data ]]
entrypointaddress: 0x179B
timedatestamp….: 0x4D3B7130 (Sun Jan 23 00:07:12 2011)
machinetype……: 0x14c (I386)

[[ 6 section(s) ]]
name, viradd, virsiz, rawdsiz, ntropy, md5
.text, 0x1000, 0x55B7, 0x6000, 4.96, fda81bf8150e98e0f5a9e1b0bc11da59
.rdata, 0x7000, 0x511, 0x1000, 1.67, 875c082d7d0878688c5fcd85ac711e5f
.data, 0x8000, 0x15AC, 0x1000, 0.97, 1481735657e01d9a1dcfddcd91f1ec10
.idata, 0xA000, 0x615, 0x1000, 1.82, 1feb328d1a685493f74a7e85f826474f
.rsrc, 0xB000, 0x97C8, 0xA000, 6.89, 80e9c6c7c13fe8539cfb4dfb3c1d8ad2
.reloc, 0x15000, 0x5DB, 0x1000, 2.60, 37b7df54ff45f10edf10e76cbaff6f31

[[ 1 import(s) ]]
KERNEL32.dll: CreateThread, LoadLibraryA, GetLastError, HeapCreate, ExitProcess, VirtualFree, lstrcatA, lstrlenA, VirtualAlloc, GetModuleHandleA, GetStartupInfoA, GetCommandLineA, GetVersion, TerminateProcess, GetCurrentProcess, UnhandledExceptionFilter, GetModuleFileNameA, FreeEnvironmentStringsA, FreeEnvironmentStringsW, WideCharToMultiByte, GetEnvironmentStrings, GetEnvironmentStringsW, SetHandleCount, GetStdHandle, GetFileType, HeapDestroy, HeapFree, RtlUnwind, WriteFile, GetCPInfo, GetACP, GetOEMCP, HeapAlloc, HeapReAlloc, IsBadWritePtr, GetProcAddress, MultiByteToWideChar, LCMapStringA, LCMapStringW, GetStringTypeA, GetStringTypeW
Prevx Info:
http://info.prevx.com/aboutprogramtext.asp…ACCDF004CE362C3
ExifTool:
file metadata
CodeSize: 24576
EntryPoint: 0x179b
FileSize: 84 kB
FileType: Win32 EXE
ImageVersion: 0.0
InitializedDataSize: 57344
LinkerVersion: 6.0
MIMEType: application/octet-stream
MachineType: Intel 386 or later, and compatibles
OSVersion: 4.0
PEType: PE32
Subsystem: Windows GUI
SubsystemVersion: 4.0
TimeStamp: 2011:01:23 01:07:12+01:00
UninitializedDataSize: 0
Symantec reputation:Suspicious.Insight
F-Secure DeepGuard:Suspicious:W32/Malware!Online

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI