This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Window XP Recovery Virus - All files are Gone/Hidden

6 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello,

Back in March I had Malware on my computer, but I fixed it via this topic http://forums.whatthetech.com/index.php?sh…17735&st=30

It appears that there are still remnance of this Malware on my computer. Currently all my files are hidden, there is nothing in my start-> all programs list, and system restore wont work.

I ran chkdsk, I rebooted in safe mode, went to folder options, chose show hidden folders. All my folder came back, and I ran Malware Bytes. I removed the infected files, restarted the computer normally and still the virus was present. I reran safe mode and Malware Bytes, and still the computer is not back to normal. The virus will not go away. Everytime I run MBAM it keeps finding at least one infected file. I also reapired windows via the Windows installation CD. Nothing has helped.

Please help.
Hi,

Download DDS and save it to your desktop from here or here or here.
Disable any script blocker, and then double click dds file to run the tool.
  • When done, DDS will open two (2) logs:
    • DDS.txt
    • Attach.txt
  • Save both reports to your desktop. Post them back to your topic.
Hello Blade, Just to let you know, I was able to stop the malware pop ups using rkill and MBAM. I was also able to unhide all of my files using the unhide software. My only problem now is most of my prior shortcuts, and most of the the program folders in start-> all programs are emply. If there anyway to fix that? Here are the two log files from DDS: . DDS (Ver_11-03-05.01) - NTFSx86 Run by [removed] at 8:01:08.09 on Sun 05/15/2011 Internet Explorer: 8.0.6001.18702 Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1015.467 [GMT -4:00] . AV: Trend Micro AntiVirus *Disabled/Updated* {7D2296BC-32CC-4519-917E-52E652474AF5} . ============== Running Processes =============== . C:\WINDOWS\system32\svchost -k DcomLaunch svchost.exe C:\WINDOWS\System32\svchost.exe -k netsvcs svchost.exe svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\ctfmon.exe svchost.exe C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe C:\Program Files\Bonjour\mDNSResponder.exe C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe C:\Program Files\Juniper Networks\Common Files\dsNcService.exe C:\Program Files\Java\jre6\bin\jqs.exe C:\Program Files\Kodak\printer\center\KodakSvc.exe C:\WINDOWS\system32\svchost.exe -k imgsvc C:\Program Files\Western Digital\WD SmartWare\WD Drive Manager\WDDMService.exe C:\Program Files\Western Digital\WD SmartWare\Front Parlor\WDFME\WDFME.exe C:\Program Files\Western Digital\WD SmartWare\Front Parlor\WDSC.exe C:\Program Files\Kodak\Printer\Center\EKDiscovery.exe C:\WINDOWS\system32\wuauclt.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Documents and Settings\Ryan\Desktop\dds.com . ============== Pseudo HJT Report =============== . uInternet Settings,ProxyOverride = *.local uURLSearchHooks: H - No File BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll EB: {32683183-48a0-441b-a342-7c2a440a9478} - No File uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe dRunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe dRunOnce: [MPlayer2_FixUp] c:\windows\inf\unregmp2.exe /Fixups IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL DPF: DirectAnimation Java Classes - file://c:\windows\java\classes\dajava.cab DPF: Microsoft XML Parser for Java - file://c:\windows\java\classes\xmldso.cab DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://go.microsoft.com/fwlink/?linkid=39204 DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1282931649608 DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1283429474781 DPF: {73ECB3AA-4717-450C-A2AB-D00DAD9EE203} - hxxp://h20270.www2.hp.com/ediags/gmn2/install/HPProductDetection2.cab DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab DPF: {F27237D7-93C8-44C2-AC6E-D6057B9A918F} - hxxps://eg.remoteaccess.thomsonreuters.com/dana-cached/sc/JuniperSetupClient.cab Notify: igfxcui - igfxdev.dll SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll . ============= SERVICES / DRIVERS =============== . R2 Kodak AiO Network Discovery Service;Kodak AiO Network Discovery Service;c:\program files\kodak\printer\center\EKDiscovery.exe [2008-10-10 274432] R2 KodakSvc;Kodak AiO Device Service;c:\program files\kodak\printer\center\KodakSvc.exe [2008-10-30 28672] R2 tmpreflt;tmpreflt;c:\windows\system32\drivers\tmpreflt.sys [2010-8-27 36432] R2 WDDMService;WDDMService;c:\program files\western digital\wd smartware\wd drive manager\WDDMService.exe [2011-3-9 238592] R2 WDFME;WD File Management Engine;c:\program files\western digital\wd smartware\front parlor\wdfme\WDFME.exe [2011-3-9 1060864] R2 WDSC;WD File Management Shadow Engine;c:\program files\western digital\wd smartware\front parlor\WDSC.exe [2011-3-9 484352] S0 nkrinjkl;nkrinjkl;c:\windows\system32\drivers\twhxykwd.sys –> c:\windows\system32\drivers\twhxykwd.sys [?] S0 qugd;qugd;c:\windows\system32\drivers\yfojj.sys –> c:\windows\system32\drivers\yfojj.sys [?] S2 tmevtmgr;tmevtmgr;c:\windows\system32\drivers\tmevtmgr.sys [2010-8-27 50256] S2 TmProxy;Trend Micro Proxy Service;c:\program files\trend micro\internet security\TmProxy.exe [2010-8-27 677128] S3 ivusb;Initio Driver for USB Default Controller;c:\windows\system32\drivers\ivusb.sys –> c:\windows\system32\drivers\ivusb.sys [?] S3 Normandy;Normandy SR2; [x] S3 WDC_SAM;WD SCSI Pass Thru driver;c:\windows\system32\drivers\wdcsam.sys [2010-9-2 11520] . =============== Created Last 30 ================ . 2011-05-15 11:37:15 274288 —-a-w- c:\windows\system32\mucltui.dll 2011-05-15 11:37:15 16736 —-a-w- c:\windows\system32\mucltui.dll.mui 2011-05-15 01:19:35 135168 -c—-w- c:\windows\system32\dllcache\shsvcs.dll 2011-05-15 01:18:14 40960 -c—-w- c:\windows\system32\dllcache\ndproxy.sys 2011-05-15 01:17:55 45568 -c—-w- c:\windows\system32\dllcache\wab.exe 2011-05-15 01:17:21 978944 -c—-w- c:\windows\system32\dllcache\mfc42.dll 2011-05-15 01:17:21 953856 -c—-w- c:\windows\system32\dllcache\mfc40u.dll 2011-05-15 01:17:03 617472 -c—-w- c:\windows\system32\dllcache\comctl32.dll 2011-05-14 16:43:33 12800 -c—-w- c:\windows\system32\dllcache\xpshims.dll 2011-05-14 16:43:32 602112 -c—-w- c:\windows\system32\dllcache\msfeeds.dll 2011-05-14 16:43:32 55296 -c—-w- c:\windows\system32\dllcache\msfeedsbs.dll 2011-05-14 16:43:31 743424 -c—-w- c:\windows\system32\dllcache\iedvtool.dll 2011-05-14 16:43:31 247808 -c—-w- c:\windows\system32\dllcache\ieproxy.dll 2011-05-14 16:43:31 1991680 -c—-w- c:\windows\system32\dllcache\iertutil.dll 2011-05-14 16:43:31 11080704 -c—-w- c:\windows\system32\dllcache\ieframe.dll 2011-05-14 16:29:20 79872 -c—-w- c:\windows\system32\dllcache\msxml6r.dll 2011-05-14 16:29:20 1372672 -c—-w- c:\windows\system32\dllcache\msxml6.dll 2011-05-14 16:28:53 81920 ——w- c:\windows\system32\ieencode.dll 2011-05-14 16:28:46 19569 —-a-w- c:\windows\005981_.tmp 2011-05-14 15:57:46 ——– d—–w- c:\program files\MSXML 6.0 2011-05-14 15:40:21 455936 -c—-w- c:\windows\system32\dllcache\mrxsmb.sys 2011-05-14 15:40:14 3558912 -c—-w- c:\windows\system32\dllcache\moviemk.exe 2011-05-14 15:39:54 357888 -c—-w- c:\windows\system32\dllcache\srv.sys 2011-05-14 15:38:50 81920 -c—-w- c:\windows\system32\dllcache\fontsub.dll 2011-05-14 15:38:50 119808 -c—-w- c:\windows\system32\dllcache\t2embed.dll 2011-05-14 15:38:39 471552 -c—-w- c:\windows\system32\dllcache\aclayers.dll 2011-05-14 15:34:09 153088 -c—-w- c:\windows\system32\dllcache\triedit.dll 2011-05-14 15:32:00 2066432 -c—-w- c:\windows\system32\dllcache\mstscax.dll 2011-05-14 15:30:34 284160 -c—-w- c:\windows\system32\dllcache\pdh.dll 2011-05-14 15:30:33 473600 -c—-w- c:\windows\system32\dllcache\fastprox.dll 2011-05-14 15:30:33 401408 -c—-w- c:\windows\system32\dllcache\rpcss.dll 2011-05-14 15:30:33 110592 -c—-w- c:\windows\system32\dllcache\services.exe 2011-05-14 15:30:32 730112 -c—-w- c:\windows\system32\dllcache\lsasrv.dll 2011-05-14 15:30:32 718336 -c—-w- c:\windows\system32\dllcache\ntdll.dll 2011-05-14 15:30:32 617472 -c—-w- c:\windows\system32\dllcache\advapi32.dll 2011-05-14 15:30:32 453120 -c—-w- c:\windows\system32\dllcache\wmiprvsd.dll 2011-05-14 15:30:32 227840 -c—-w- c:\windows\system32\dllcache\wmiprvse.exe 2011-05-14 15:30:31 2148864 -c—-w- c:\windows\system32\dllcache\ntkrnlmp.exe 2011-05-14 15:30:30 2192768 -c—-w- c:\windows\system32\dllcache\ntoskrnl.exe 2011-05-14 15:30:29 2027008 -c—-w- c:\windows\system32\dllcache\ntkrpamp.exe 2011-05-14 15:28:36 337408 -c—-w- c:\windows\system32\dllcache\netapi32.dll 2011-05-14 15:28:16 331776 -c—-w- c:\windows\system32\dllcache\msadce.dll 2011-05-14 15:27:20 203136 -c—-w- c:\windows\system32\dllcache\rmcast.sys 2011-05-14 15:21:41 ——– d—–w- c:\windows\system32\Service 2011-05-14 14:46:24 ——– d—–w- c:\windows\system32\wbem\repository.001\FS 2011-05-14 14:46:24 ——– d—–w- c:\windows\system32\wbem\Repository.001 2011-05-14 13:26:01 1082368 —-a-w- c:\windows\system32\esent.dll 2011-05-14 13:00:06 354816 —-a-w- c:\windows\system32\winhttp.dll 2011-05-14 13:00:06 18944 —-a-w- c:\windows\system32\qmgrprxy.dll 2011-05-14 12:24:55 98816 —-a-w- c:\windows\sed.exe 2011-05-14 12:24:55 89088 —-a-w- c:\windows\MBR.exe 2011-05-14 12:24:55 256512 —-a-w- c:\windows\PEV.exe 2011-05-14 12:24:55 161792 —-a-w- c:\windows\SWREG.exe 2011-05-14 12:24:44 ——– d-s—w- C:\ComboFix 2011-05-13 20:10:41 217816 —-a-w- c:\windows\system32\wuaucpl.cpl 2011-05-13 20:06:59 135168 —-a-w- c:\windows\system32\igfxres.dll 2011-05-13 18:24:59 98304 -c–a-w- c:\windows\system32\dllcache\msir3jp.dll 2011-05-13 18:23:50 18944 -c–a-w- c:\windows\system32\dllcache\cprofile.exe 2011-05-13 18:21:48 45568 —-a-w- c:\windows\system32\safrslv.dll 2011-05-13 18:20:21 281088 —-a-w- c:\program files\windows nt\pinball\pinball.exe 2011-05-13 18:19:58 95232 —-a-w- c:\windows\system32\wbem\wmiutils.dll 2011-05-13 18:18:54 57600 —-a-w- c:\windows\system32\drivers\redbook.sys 2011-05-13 18:18:53 20992 —-a-w- c:\windows\system32\drivers\rtl8139.sys 2011-05-13 18:18:19 4096 —-a-w- c:\windows\system32\ksuser.dll 2011-05-13 18:18:19 129536 —-a-w- c:\windows\system32\ksproxy.ax 2011-05-13 18:17:45 40840 —-a-w- c:\windows\system32\drivers\termdd.sys 2011-05-13 18:17:14 741376 —-a-w- c:\program files\common files\microsoft shared\speech\sapi.dll 2011-05-13 18:17:07 24661 -c–a-w- c:\windows\system32\dllcache\spxcoins.dll 2011-05-13 18:17:07 24661 —-a-w- c:\windows\system32\spxcoins.dll 2011-05-13 18:17:07 146432 —-a-w- c:\windows\system\winspool.drv 2011-05-13 18:17:07 13312 -c–a-w- c:\windows\system32\dllcache\irclass.dll 2011-05-13 18:17:07 13312 —-a-w- c:\windows\system32\irclass.dll 2011-05-13 18:17:07 11264 —-a-w- c:\windows\system32\drivers\irenum.sys 2011-05-13 18:17:06 74752 —-a-w- c:\windows\system32\storprop.dll 2011-05-13 18:16:54 7046 —-a-r- c:\windows\SET102.tmp 2011-05-13 18:16:52 13608 —-a-r- c:\windows\SETE4.tmp 2011-05-13 18:16:48 1086182 —-a-r- c:\windows\SETCF.tmp 2011-05-12 00:34:23 ——– d—–w- c:\windows\system32\wbem\repository\FS 2011-05-12 00:34:23 ——– d—–w- c:\windows\system32\wbem\Repository 2011-04-16 04:54:03 ——– d-sha-r- C:\cmdcons . ==================== Find3M ==================== . 2011-03-07 05:33:50 692736 —-a-w- c:\windows\system32\inetcomm.dll 2011-03-04 06:37:06 420864 —-a-w- c:\windows\system32\vbscript.dll 2011-03-03 13:21:11 1857920 —-a-w- c:\windows\system32\win32k.sys 2011-02-22 23:06:29 916480 —-a-w- c:\windows\system32\wininet.dll 2011-02-22 23:06:29 43520 —-a-w- c:\windows\system32\licmgr10.dll 2011-02-22 23:06:29 1469440 ——w- c:\windows\system32\inetcpl.cpl 2011-02-22 11:41:59 385024 —-a-w- c:\windows\system32\html.iec 2011-02-18 21:36:58 4184352 —-a-w- c:\windows\system32\usbaaplrc.dll 2011-02-17 12:32:12 5120 —-a-w- c:\windows\system32\xpsp4res.dll 2011-02-15 12:56:39 290432 —-a-w- c:\windows\system32\atmfd.dll . ============= FINISH: 8:02:15.73 =============== . UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG. IF REQUESTED, ZIP IT UP & ATTACH IT . DDS (Ver_11-03-05.01) . Microsoft Windows XP Home Edition Boot Device: \Device\HarddiskVolume2 Install Date: 5/13/2011 2:26:06 PM System Uptime: 5/15/2011 7:57:00 AM (1 hours ago) . Motherboard: ASUSTeK Computer INC. | | Goldfish3 Processor: Intel® Pentium® 4 CPU 3.00GHz | CPU 1 | 3001/200mhz . ==== Disk Partitions ========================= . C: is FIXED (NTFS) - 179 GiB total, 125.937 GiB free. E: is Removable F: is Removable G: is Removable H: is FIXED (FAT32) - 7 GiB total, 1.656 GiB free. I: is CDROM (UDF) J: is CDROM () K: is Removable . ==== Disabled Device Manager Items ============= . ==== System Restore Points =================== . RP1: 5/13/2011 4:07:20 PM - System Checkpoint RP2: 5/14/2011 9:00:12 AM - Software Distribution Service 3.0 RP3: 5/14/2011 9:00:31 AM - Installed Windows XP KB842773. RP4: 5/14/2011 9:01:12 AM - Installed Windows Installer KB893803v2. RP5: 5/14/2011 9:24:28 AM - Software Distribution Service 3.0 RP6: 5/14/2011 9:30:33 AM - Software Distribution Service 3.0 RP7: 5/14/2011 9:30:55 AM - Installed Windows XP KB890859. RP8: 5/14/2011 9:31:33 AM - Installed Windows XP KB914389. RP9: 5/14/2011 9:31:58 AM - Installed Windows XP KB920683. RP10: 5/14/2011 9:32:22 AM - Installed Windows XP KB908519. RP11: 5/14/2011 9:32:45 AM - Installed Windows XP KB835409. RP12: 5/14/2011 9:42:34 AM - Installed Windows XP KB896428. RP13: 5/14/2011 9:43:01 AM - Installed Windows XP KB913580. RP14: 5/14/2011 9:43:28 AM - Installed Windows XP KB905749. RP15: 5/14/2011 9:43:55 AM - Installed Windows XP KB908531. RP16: 5/14/2011 9:44:26 AM - Installed Windows XP KB904706. RP17: 5/14/2011 9:44:45 AM - Installed Windows XP KB911567. RP18: 5/14/2011 9:45:15 AM - Installed Windows XP KB918899. RP19: 5/14/2011 9:46:02 AM - Installed Windows XP KB912919. RP20: 5/14/2011 9:46:32 AM - Installed Windows XP KB900725. RP21: 5/14/2011 9:47:00 AM - Installed Windows XP KB888302. RP22: 5/14/2011 9:47:28 AM - Installed Windows XP KB917422. RP23: 5/14/2011 9:47:58 AM - Installed Windows XP KB923191. RP24: 5/14/2011 9:48:27 AM - Installed Windows XP KB901214. RP25: 5/14/2011 9:49:08 AM - Installed Windows Media Player 8 KB917734_WMP8. RP26: 5/14/2011 9:49:34 AM - Installed Windows XP KB917953. RP27: 5/14/2011 9:50:00 AM - Installed Windows XP KB905414. RP28: 5/14/2011 9:50:25 AM - Installed Windows XP KB917344. RP29: 5/14/2011 9:50:54 AM - Installed Windows XP KB914388. RP30: 5/14/2011 9:51:27 AM - Installed Windows XP KB919007. RP31: 5/14/2011 9:51:54 AM - Installed Windows XP KB890046. RP32: 5/14/2011 9:52:21 AM - Installed Windows XP KB891781. RP33: 5/14/2011 9:52:49 AM - Installed Windows XP KB920670. RP34: 5/14/2011 9:53:24 AM - Installed Windows XP KB902400. RP35: 5/14/2011 9:54:17 AM - Installed Windows Media Player KB911564. RP36: 5/14/2011 9:54:39 AM - Installed Windows XP KB905495. RP37: 5/14/2011 9:55:08 AM - Installed Windows XP KB910437. RP38: 5/14/2011 9:55:39 AM - Installed Windows XP KB896358. RP39: 5/14/2011 9:55:58 AM - Installed Windows XP KB918439. RP40: 5/14/2011 9:56:30 AM - Installed Windows XP KB921398. RP41: 5/14/2011 9:56:51 AM - Installed Windows XP KB925486. RP42: 5/14/2011 9:57:21 AM - Installed Windows XP KB924496. RP43: 5/14/2011 9:57:49 AM - Installed Windows XP KB914798. RP44: 5/14/2011 9:58:14 AM - Installed Windows XP KB873339. RP45: 5/14/2011 10:02:09 AM - Installed Windows XP KB896423. RP46: 5/14/2011 10:02:38 AM - Installed Windows XP KB911562. RP47: 5/14/2011 10:02:56 AM - Installed Windows XP KB833407. RP48: 5/14/2011 10:03:26 AM - Installed Windows XP KB911280. RP49: 5/14/2011 10:04:01 AM - Installed Windows XP KB893756. RP50: 5/14/2011 10:04:34 AM - Installed Windows XP KB896424. RP51: 5/14/2011 10:05:07 AM - Installed Windows XP KB920685. RP52: 5/14/2011 10:05:38 AM - Installed Windows XP KB899591. RP53: 5/14/2011 10:06:08 AM - Installed Windows XP KB901017. RP54: 5/14/2011 10:06:40 AM - Installed Windows XP KB922616. RP55: 5/14/2011 10:07:11 AM - Installed Windows XP KB911927. RP56: 5/14/2011 10:07:43 AM - Installed Windows XP KB921883. RP57: 5/14/2011 10:08:14 AM - Installed Windows XP KB923414. RP58: 5/14/2011 10:08:44 AM - Installed Windows XP KB885836. RP59: 5/14/2011 10:09:22 AM - Installed Windows XP KB885835. RP60: 5/14/2011 10:09:58 AM - Installed Windows XP KB922819. RP61: 5/14/2011 10:10:35 AM - Installed Windows XP KB924191. RP62: 5/14/2011 10:11:05 AM - Installed Windows XP KB899587. RP63: 5/14/2011 10:15:59 AM - Software Distribution Service 3.0 RP64: 5/14/2011 10:25:53 AM - Installed Windows XP Service Pack 2. RP65: 5/14/2011 10:50:01 AM - Installed Windows XP KB873339. RP66: 5/14/2011 10:50:37 AM - Installed Windows XP KB885835. RP67: 5/14/2011 10:51:11 AM - Installed Windows XP KB885836. RP68: 5/14/2011 10:51:44 AM - Installed Windows XP KB888302. RP69: 5/14/2011 10:52:18 AM - Installed Windows XP KB890046. RP70: 5/14/2011 10:52:56 AM - Installed Windows XP KB890859. RP71: 5/14/2011 10:53:36 AM - Installed Windows XP KB891781. RP72: 5/14/2011 10:54:12 AM - Installed Windows XP KB893756. RP73: 5/14/2011 10:54:47 AM - Installed Windows XP KB896358. RP74: 5/14/2011 10:55:22 AM - Installed Windows XP KB896423. RP75: 5/14/2011 10:56:00 AM - Installed Windows XP KB896424. RP76: 5/14/2011 10:56:36 AM - Installed Windows XP KB896428. RP77: 5/14/2011 10:57:12 AM - Installed Windows XP KB899587. RP78: 5/14/2011 10:57:45 AM - Installed Windows XP KB899591. RP79: 5/14/2011 10:58:20 AM - Installed Windows XP KB900725. RP80: 5/14/2011 10:58:57 AM - Installed Windows XP KB901017. RP81: 5/14/2011 10:59:32 AM - Installed Windows XP KB901214. RP82: 5/14/2011 11:00:11 AM - Installed Windows XP KB902400. RP83: 5/14/2011 11:00:53 AM - Installed Windows XP KB904706. RP84: 5/14/2011 11:01:28 AM - Installed Windows XP KB905414. RP85: 5/14/2011 11:02:02 AM - Installed Windows XP KB905749. RP86: 5/14/2011 11:02:37 AM - Installed Windows XP KB908519. RP87: 5/14/2011 11:03:12 AM - Installed Windows XP KB908531. RP88: 5/14/2011 11:03:48 AM - Installed Windows XP KB910437. RP89: 5/14/2011 11:04:22 AM - Installed Windows XP KB911280. RP90: 5/14/2011 11:04:56 AM - Installed Windows XP KB911562. RP91: 5/14/2011 11:05:30 AM - Installed Windows XP KB911927. RP92: 5/14/2011 11:06:04 AM - Installed Windows XP KB912919. RP93: 5/14/2011 11:06:43 AM - Installed Windows XP KB913580. RP94: 5/14/2011 11:07:19 AM - Installed Windows XP KB914388. RP95: 5/14/2011 11:07:53 AM - Installed Windows XP KB914389. RP96: 5/14/2011 11:08:29 AM - Installed Windows XP KB917344. RP97: 5/14/2011 11:09:01 AM - Installed Windows XP KB917422. RP98: 5/14/2011 11:09:37 AM - Installed Windows XP KB917953. RP99: 5/14/2011 11:10:11 AM - Installed Windows XP KB919007. RP100: 5/14/2011 11:10:47 AM - Installed Windows XP KB920670. RP101: 5/14/2011 11:11:22 AM - Installed Windows XP KB920683. RP102: 5/14/2011 11:11:56 AM - Installed Windows XP KB920685. RP103: 5/14/2011 11:12:33 AM - Installed Windows XP KB921398. RP104: 5/14/2011 11:13:09 AM - Installed Windows XP KB921883. RP105: 5/14/2011 11:13:44 AM - Installed Windows XP KB922616. RP106: 5/14/2011 11:14:18 AM - Installed Windows XP KB922819. RP107: 5/14/2011 11:14:51 AM - Installed Windows XP KB923191. RP108: 5/14/2011 11:15:27 AM - Installed Windows XP KB923414. RP109: 5/14/2011 11:16:04 AM - Installed Windows XP KB924191. RP110: 5/14/2011 11:16:39 AM - Installed Windows XP KB924496. RP111: 5/14/2011 11:43:14 AM - Software Distribution Service 3.0 RP112: 5/14/2011 12:35:57 PM - Software Distribution Service 3.0 RP113: 5/14/2011 12:49:07 PM - Software Distribution Service 3.0 RP114: 5/14/2011 8:58:34 PM - Software Distribution Service 3.0 RP115: 5/14/2011 9:23:59 PM - Software Distribution Service 3.0 RP116: 5/14/2011 9:46:20 PM - Software Distribution Service 3.0 RP117: 5/15/2011 7:47:45 AM - Software Distribution Service 3.0 . ==== Installed Programs ====================== . Adobe Flash Player 10 ActiveX Adobe Reader 9.4.4 Agere Systems PCI Soft Modem aiofw aioocr aioprnt aioscnnr Apple Application Support Apple Mobile Device Support Apple Software Update Bonjour CCScore center DivX Setup Dr. DivX 2.0 OSS Easy CD Creator 5 Basic eMule ESSBrwr ESSCDBK ESScore ESSgui ESSini ESSPCD ESSPDock ESSTOOLS essvatgt Help_CTR helptut helpug Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595) Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484) HP Product Detection Intel® Graphics Media Accelerator Driver iTunes Java Auto Updater Java™ 6 Update 21 Juniper Networks Host Checker Juniper Networks Network Connect 6.5.0 Juniper Networks Network Connect 7.0.0 Juniper Networks Setup Client Kodak EasyShare software ksdip LaCie Backup Software v1.5.2215 Malwarebytes' Anti-Malware Media Player Classic - Home Cinema v. 1.3.1249.0 Microsoft .NET Framework 1.1 Microsoft .NET Framework 1.1 Security Update (KB2416447) Microsoft .NET Framework 1.1 Security Update (KB979906) Microsoft .NET Framework 2.0 Service Pack 2 Microsoft .NET Framework 3.0 Service Pack 2 Microsoft .NET Framework 3.5 SP1 Microsoft Compression Client Pack 1.0 for Windows XP Microsoft Office Professional Edition 2003 Microsoft User-Mode Driver Framework Feature Pack 1.0 Microsoft Windows XP Video Decoder Checkup Utility MSXML 4.0 SP2 (KB954430) MSXML 4.0 SP2 (KB973688) MSXML 6 Service Pack 2 (KB973686) netbrdg OfotoXMI QuickTime Realtek High Definition Audio Driver Security Update for Microsoft .NET Framework 3.5 SP1 (KB2416473) Security Update for Windows Internet Explorer 8 (KB2497640) Security Update for Windows Internet Explorer 8 (KB2510531) Security Update for Windows Media Player 8 (KB917734) Security Update for Windows XP (KB2229593) Security Update for Windows XP (KB2412687) Security Update for Windows XP (KB2485663) Security Update for Windows XP (KB2503658) Security Update for Windows XP (KB2506212) Security Update for Windows XP (KB2506223) Security Update for Windows XP (KB2507618) Security Update for Windows XP (KB2508272) Security Update for Windows XP (KB2508429) Security Update for Windows XP (KB2509553) Security Update for Windows XP (KB2511455) Security Update for Windows XP (KB2524375) Security Update for Windows XP (KB923561) Security Update for Windows XP (KB923789) Security Update for Windows XP (KB946648) Security Update for Windows XP (KB953155) SES Driver SFR SHASTA skin0001 SKINXSDK Sony Picture Utility Sony USB Driver staticcr TEZ-Server TEZ-WorkStation Trend Micro AntiVirus Update for Microsoft .NET Framework 3.5 SP1 (KB963707) VC80CRTRedist - 8.0.50727.4053 VLC media player 1.1.4 VPRINTOL WD SmartWare WD Software Upgrader WebFldrs XP Windows Genuine Advantage Validation Tool (KB892130) Windows Internet Explorer 8 Windows Media Format 11 runtime Windows Media Player 11 Windows XP Service Pack 3 WinRAR archiver WinZip 14.5 WIRELESS . ==== Event Viewer Messages From Past Week ======== . 5/14/2011 9:25:03 AM, error: Windows Update Agent [20] - Installation Failure: Windows failed to install the following update with error 0x80070020: Windows XP Service Pack 2. 5/14/2011 9:04:47 AM, error: Service Control Manager [7001] - The SSDP Discovery Service service depends on the HTTP service which failed to start because of the following error: The specified procedure could not be found. 5/14/2011 9:04:47 AM, error: Service Control Manager [7000] - The HTTP service failed to start due to the following error: The specified procedure could not be found. 5/14/2011 9:04:45 AM, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: FltMgr OMCI 5/14/2011 9:04:44 AM, error: Service Control Manager [7022] - The DCOM Server Process Launcher service hung on starting. 5/14/2011 9:04:44 AM, error: Service Control Manager [7000] - The Security Center service failed to start due to the following error: The executable program that this service is configured to run in does not implement the service. 5/14/2011 9:04:29 AM, error: SideBySide [59] - Resolve Partial Assembly failed for Microsoft.VC90.CRT. Reference error message: The referenced assembly is not installed on your system. . 5/14/2011 9:04:29 AM, error: SideBySide [59] - Generate Activation Context failed for C:\Program Files\Western Digital\WD SmartWare\Front Parlor\XP\Shadow.dll. Reference error message: The operation completed successfully. . 5/14/2011 9:04:29 AM, error: SideBySide [32] - Dependent Assembly Microsoft.VC90.CRT could not be found and Last Error was The referenced assembly is not installed on your system. 5/14/2011 7:50:31 AM, error: Service Control Manager [7023] - The System Restore Service service terminated with the following error: Access is denied. 5/14/2011 7:49:51 AM, error: SRService [104] - The System Restore initialization process failed. 5/14/2011 11:38:05 AM, error: Service Control Manager [7034] - The WD File Management Engine service terminated unexpectedly. It has done this 1 time(s). 5/14/2011 11:24:29 AM, error: Service Control Manager [7023] - The Portable Media Serial Number service terminated with the following error: The specified module could not be found. 5/14/2011 11:24:29 AM, error: Service Control Manager [7022] - The Windows Firewall/Internet Connection Sharing (ICS) service hung on starting. 5/13/2011 7:52:39 PM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service EventSystem with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF} 5/13/2011 5:16:24 PM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service StiSvc with arguments "" in order to run the server: {A1F4E726-8CF1-11D1-BF92-0060081ED811} 5/13/2011 5:15:52 PM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service netman with arguments "" in order to run the server: {BA126AE5-2166-11D1-B1D0-00805FC1270E} 5/13/2011 5:15:16 PM, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: AFD cdudf_xp Fips FltMgr IPSec MRxSmb NetBIOS NetBT ohci1394 OMCI Processor RasAcd Rdbss Tcpip tmtdi 5/13/2011 5:15:16 PM, error: Service Control Manager [7001] - The Trend Micro Proxy Service service depends on the Trend Micro TDI Driver service which failed to start because of the following error: A device attached to the system is not functioning. 5/13/2011 5:15:16 PM, error: Service Control Manager [7001] - The TCP/IP NetBIOS Helper service depends on the AFD Networking Support Environment service which failed to start because of the following error: A device attached to the system is not functioning. 5/13/2011 5:15:16 PM, error: Service Control Manager [7001] - The Network Location Awareness (NLA) service depends on the AFD Networking Support Environment service which failed to start because of the following error: A device attached to the system is not functioning. 5/13/2011 5:15:16 PM, error: Service Control Manager [7001] - The Messenger service depends on the NetBIOS Interface service which failed to start because of the following error: A device attached to the system is not functioning. 5/13/2011 5:15:16 PM, error: Service Control Manager [7001] - The Kodak AiO Network Discovery Service service depends on the Bonjour Service service which failed to start because of the following error: The dependency service or group failed to start. 5/13/2011 5:15:16 PM, error: Service Control Manager [7001] - The IPSEC Services service depends on the IPSEC driver service which failed to start because of the following error: A device attached to the system is not functioning. 5/13/2011 5:15:16 PM, error: Service Control Manager [7001] - The DNS Client service depends on the TCP/IP Protocol Driver service which failed to start because of the following error: A device attached to the system is not functioning. 5/13/2011 5:15:16 PM, error: Service Control Manager [7001] - The DHCP Client service depends on the NetBios over Tcpip service which failed to start because of the following error: A device attached to the system is not functioning. 5/13/2011 5:15:16 PM, error: Service Control Manager [7001] - The Bonjour Service service depends on the TCP/IP Protocol Driver service which failed to start because of the following error: A device attached to the system is not functioning. 5/13/2011 5:15:16 PM, error: Service Control Manager [7001] - The Apple Mobile Device service depends on the TCP/IP Protocol Driver service which failed to start because of the following error: A device attached to the system is not functioning. 5/13/2011 5:08:00 PM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service netman with arguments "" in order to run the server: {BA126AD1-2166-11D1-B1D0-00805FC1270E} 5/13/2011 4:57:22 PM, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: AFD cdudf_xp Fips FltMgr IPSec MRxSmb NetBIOS NetBT OMCI Processor RasAcd Rdbss Tcpip tmtdi 5/13/2011 3:36:01 PM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service SfCtlCom with arguments "" in order to run the server: {1A65BAB7-30B1-4FB7-BC13-D00C28FCF605} 5/13/2011 2:27:26 PM, error: Setup [60055] - Windows Setup encountered non-fatal errors during installation. Please check the setuperr.log found in your Windows directory for more information. 5/13/2011 2:22:43 PM, error: DCOM [10005] - DCOM got error "%1058" attempting to start the service SENS with arguments "" in order to run the server: {D3938AB0-5B9D-11D1-8DD2-00AA004ABD5E} 5/13/2011 12:07:17 PM, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: OMCI 5/13/2011 12:07:15 PM, error: sr [1] - The System Restore filter encountered the unexpected error '0xC0000001' while processing the file '' on the volume 'HarddiskVolume2'. It has stopped monitoring the volume. 5/13/2011 11:10:23 AM, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: AFD cdudf_xp Fips intelppm IPSec MRxSmb NetBIOS NetBT OMCI RasAcd Rdbss Tcpip tmtdi 5/13/2011 10:44:10 AM, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: AFD cdudf_xp Fips intelppm IPSec MRxSmb NetBIOS NetBT ohci1394 OMCI RasAcd Rdbss Tcpip tmtdi 5/13/2011 10:43:44 AM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service BITS with arguments "" in order to run the server: {4991D34B-80A1-4291-83B6-3328366B9097} . ==== End Of File ===========================

Just to let you know, I was able to stop the malware pop ups using rkill and MBAM.

and you also did a ComboFix run which should be done only if advised by a trained helper. Copy-paste c:\ComboFix.txt file contents + MBAM report contents.
ComboFix 11-05-14.03 - Ryan 05/15/2011 11:31:03.3.2 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1015.452 [GMT -4:00]
Running from: c:\iexplore2\ComboFix.exe
Command switches used :: ComboFix
AV: Trend Micro AntiVirus *Disabled/Updated* {7D2296BC-32CC-4519-917E-52E652474AF5}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\windows\system32\service
c:\windows\system32\service\14052011_TIS17_SfFniAU.log
.
.
((((((((((((((((((((((((( Files Created from 2011-04-15 to 2011-05-15 )))))))))))))))))))))))))))))))
.
.
2011-05-15 11:37 . 2009-08-06 23:23 274288 —-a-w- c:\windows\system32\mucltui.dll
2011-05-15 01:19 . 2009-07-27 23:17 135168 -c—-w- c:\windows\system32\dllcache\shsvcs.dll
2011-05-15 01:18 . 2010-11-02 15:17 40960 -c—-w- c:\windows\system32\dllcache\ndproxy.sys
2011-05-15 01:17 . 2010-10-11 14:59 45568 -c—-w- c:\windows\system32\dllcache\wab.exe
2011-05-15 01:17 . 2011-02-08 13:33 978944 -c—-w- c:\windows\system32\dllcache\mfc42.dll
2011-05-15 01:17 . 2010-09-18 06:53 953856 -c—-w- c:\windows\system32\dllcache\mfc40u.dll
2011-05-15 01:17 . 2010-08-23 16:12 617472 -c—-w- c:\windows\system32\dllcache\comctl32.dll
2011-05-14 16:43 . 2011-02-22 23:06 12800 -c—-w- c:\windows\system32\dllcache\xpshims.dll
2011-05-14 16:43 . 2011-02-22 23:06 602112 -c—-w- c:\windows\system32\dllcache\msfeeds.dll
2011-05-14 16:43 . 2011-02-22 23:06 55296 -c—-w- c:\windows\system32\dllcache\msfeedsbs.dll
2011-05-14 16:43 . 2011-02-22 23:06 743424 -c—-w- c:\windows\system32\dllcache\iedvtool.dll
2011-05-14 16:43 . 2011-02-22 23:06 247808 -c—-w- c:\windows\system32\dllcache\ieproxy.dll
2011-05-14 16:43 . 2011-02-22 23:06 1991680 -c—-w- c:\windows\system32\dllcache\iertutil.dll
2011-05-14 16:43 . 2011-02-22 23:06 11080704 -c—-w- c:\windows\system32\dllcache\ieframe.dll
2011-05-14 16:29 . 2009-07-31 14:05 1372672 -c—-w- c:\windows\system32\dllcache\msxml6.dll
2011-05-14 16:29 . 2008-04-13 17:27 79872 -c—-w- c:\windows\system32\dllcache\msxml6r.dll
2011-05-14 16:28 . 2008-04-14 00:11 81920 ——w- c:\windows\system32\ieencode.dll
2011-05-14 16:28 . 2006-12-28 19:01 19569 —-a-w- c:\windows\005981_.tmp
2011-05-14 15:57 . 2011-05-14 15:57 ——– d—–w- c:\program files\MSXML 6.0
2011-05-14 15:40 . 2011-02-17 13:18 455936 -c—-w- c:\windows\system32\dllcache\mrxsmb.sys
2011-05-14 15:40 . 2010-06-18 13:36 3558912 -c—-w- c:\windows\system32\dllcache\moviemk.exe
2011-05-14 15:39 . 2011-02-17 13:18 357888 -c—-w- c:\windows\system32\dllcache\srv.sys
2011-05-14 15:38 . 2010-08-27 08:02 119808 -c—-w- c:\windows\system32\dllcache\t2embed.dll
2011-05-14 15:38 . 2009-10-15 16:28 81920 -c—-w- c:\windows\system32\dllcache\fontsub.dll
2011-05-14 15:38 . 2009-11-21 15:51 471552 -c—-w- c:\windows\system32\dllcache\aclayers.dll
2011-05-14 15:34 . 2009-06-21 22:04 153088 -c—-w- c:\windows\system32\dllcache\triedit.dll
2011-05-14 15:32 . 2009-06-10 13:19 2066432 -c—-w- c:\windows\system32\dllcache\mstscax.dll
2011-05-14 15:30 . 2009-03-06 14:22 284160 -c—-w- c:\windows\system32\dllcache\pdh.dll
2011-05-14 15:30 . 2009-02-09 12:10 473600 -c—-w- c:\windows\system32\dllcache\fastprox.dll
2011-05-14 15:30 . 2009-02-09 12:10 401408 -c—-w- c:\windows\system32\dllcache\rpcss.dll
2011-05-14 15:30 . 2009-02-06 11:11 110592 -c—-w- c:\windows\system32\dllcache\services.exe
2011-05-14 15:30 . 2010-12-20 17:26 730112 -c—-w- c:\windows\system32\dllcache\lsasrv.dll
2011-05-14 15:30 . 2010-12-09 15:15 718336 -c—-w- c:\windows\system32\dllcache\ntdll.dll
2011-05-14 15:30 . 2009-02-09 12:10 617472 -c—-w- c:\windows\system32\dllcache\advapi32.dll
2011-05-14 15:30 . 2009-02-09 12:10 453120 -c—-w- c:\windows\system32\dllcache\wmiprvsd.dll
2011-05-14 15:30 . 2009-02-06 10:10 227840 -c—-w- c:\windows\system32\dllcache\wmiprvse.exe
2011-05-14 15:30 . 2010-12-09 13:42 2148864 -c—-w- c:\windows\system32\dllcache\ntkrnlmp.exe
2011-05-14 15:30 . 2010-12-09 13:38 2192768 -c—-w- c:\windows\system32\dllcache\ntoskrnl.exe
2011-05-14 15:30 . 2010-12-09 13:07 2027008 -c—-w- c:\windows\system32\dllcache\ntkrpamp.exe
2011-05-14 15:28 . 2008-10-15 16:34 337408 -c—-w- c:\windows\system32\dllcache\netapi32.dll
2011-05-14 15:28 . 2008-05-01 14:33 331776 -c—-w- c:\windows\system32\dllcache\msadce.dll
2011-05-14 15:27 . 2008-05-08 14:02 203136 -c—-w- c:\windows\system32\dllcache\rmcast.sys
2011-05-14 13:26 . 2008-04-14 00:11 1082368 —-a-w- c:\windows\system32\esent.dll
2011-05-14 13:00 . 2009-08-25 09:17 354816 —-a-w- c:\windows\system32\winhttp.dll
2011-05-14 13:00 . 2008-04-14 00:12 18944 —-a-w- c:\windows\system32\qmgrprxy.dll
2011-05-13 20:10 . 2009-08-06 23:24 217816 —-a-w- c:\windows\system32\wuaucpl.cpl
2011-05-13 20:06 . 2005-11-03 19:21 135168 —-a-w- c:\windows\system32\igfxres.dll
2011-05-13 18:24 . 2002-09-03 16:25 98304 -c–a-w- c:\windows\system32\dllcache\msir3jp.dll
2011-05-13 18:23 . 2002-09-03 16:29 18944 -c–a-w- c:\windows\system32\dllcache\cprofile.exe
2011-05-13 18:21 . 2008-04-14 00:12 45568 —-a-w- c:\windows\system32\safrslv.dll
2011-05-13 18:20 . 2008-04-14 00:12 281088 —-a-w- c:\program files\Windows NT\Pinball\pinball.exe
2011-05-13 18:19 . 2009-02-09 12:10 453120 —-a-w- c:\windows\system32\wbem\wmiprvsd.dll
2011-05-13 18:18 . 2008-04-13 18:40 57600 —-a-w- c:\windows\system32\drivers\redbook.sys
2011-05-13 18:18 . 2004-08-04 05:31 20992 —-a-w- c:\windows\system32\drivers\rtl8139.sys
2011-05-13 18:18 . 2008-04-14 00:12 129536 —-a-w- c:\windows\system32\ksproxy.ax
2011-05-13 18:18 . 2008-04-14 00:11 4096 —-a-w- c:\windows\system32\ksuser.dll
2011-05-13 18:17 . 2008-04-14 00:13 40840 —-a-w- c:\windows\system32\drivers\termdd.sys
2011-05-13 18:17 . 2008-04-14 00:12 741376 —-a-w- c:\program files\Common Files\Microsoft Shared\Speech\sapi.dll
2011-05-13 18:17 . 2008-04-14 00:12 146432 —-a-w- c:\windows\system\winspool.drv
2011-05-13 18:17 . 2008-04-13 18:54 11264 —-a-w- c:\windows\system32\drivers\irenum.sys
2011-05-13 18:17 . 2002-09-03 17:04 24661 -c–a-w- c:\windows\system32\dllcache\spxcoins.dll
2011-05-13 18:17 . 2002-09-03 17:04 24661 —-a-w- c:\windows\system32\spxcoins.dll
2011-05-13 18:17 . 2002-09-03 16:35 13312 -c–a-w- c:\windows\system32\dllcache\irclass.dll
2011-05-13 18:17 . 2002-09-03 16:35 13312 —-a-w- c:\windows\system32\irclass.dll
2011-05-13 18:17 . 2008-04-14 00:12 74752 —-a-w- c:\windows\system32\storprop.dll
2011-05-13 18:16 . 2002-09-03 17:16 7046 —-a-r- c:\windows\SET102.tmp
2011-05-13 18:16 . 2002-09-03 16:35 13608 —-a-r- c:\windows\SETE4.tmp
2011-05-13 18:16 . 2002-09-03 16:50 1086182 —-a-r- c:\windows\SETCF.tmp
2011-05-13 14:21 . 2011-05-13 20:58 ——– d—–w- c:\documents and settings\Administrator
2011-05-12 00:34 . 2011-05-14 15:21 ——– d—–w- c:\windows\system32\wbem\Repository
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-03-04 06:37 . 2002-09-03 17:09 420864 —-a-w- c:\windows\system32\vbscript.dll
2011-03-03 13:21 . 2002-09-03 17:11 1857920 —-a-w- c:\windows\system32\win32k.sys
2011-02-22 23:06 . 2002-09-03 16:39 43520 —-a-w- c:\windows\system32\licmgr10.dll
2011-02-22 23:06 . 2002-09-03 16:35 1469440 ——w- c:\windows\system32\inetcpl.cpl
2011-02-22 11:41 . 2004-08-04 05:59 385024 —-a-w- c:\windows\system32\html.iec
2011-02-18 21:36 . 2010-08-28 22:23 41984 —-a-w- c:\windows\system32\drivers\usbaapl.sys
2011-02-18 21:36 . 2010-08-28 22:23 4184352 —-a-w- c:\windows\system32\usbaaplrc.dll
2011-02-17 13:18 . 2002-09-03 16:42 455936 —-a-w- c:\windows\system32\drivers\mrxsmb.sys
2011-02-17 13:18 . 2002-09-03 17:04 357888 —-a-w- c:\windows\system32\drivers\srv.sys
2011-02-17 12:32 . 2010-08-27 18:28 5120 —-a-w- c:\windows\system32\xpsp4res.dll
2011-02-16 20:52 . 2010-09-02 16:45 11520 —-a-w- c:\windows\system32\drivers\wdcsam.sys
2011-02-15 12:56 . 2002-09-03 16:27 290432 —-a-w- c:\windows\system32\atmfd.dll
.
.
——- Sigcheck ——-
.
[-] 2009-01-31 00:33 . 051B1BDECD6DEE18C771B5D5EC7F044D . 27136 . . [11.0.5721.5262] . . c:\windows\ERDNT\cache\mspmsnsv.dll
[-] 2009-01-31 00:33 . 051B1BDECD6DEE18C771B5D5EC7F044D . 27136 . . [11.0.5721.5262] . . c:\windows\system32\mspmsnsv.dll
[7] 2008-04-14 00:12 . C7E39EA41233E9F5B86C8DA3A9F1E4A8 . 52224 . . [9.0.1.56] . . c:\windows\$NtUninstallWMFDist11$\mspmsnsv.dll
[7] 2004-08-04 07:56 . C086483E3DBA8C1C0A687EC8D5B3D4C1 . 52224 . . [9.0.1.56] . . c:\windows\ServicePackFiles\i386\mspmsnsv.dll
[7] 2004-08-04 07:56 . C086483E3DBA8C1C0A687EC8D5B3D4C1 . 52224 . . [9.0.1.56] . . c:\windows\SoftwareDistribution\Download\16b2c96a0c41f4dfdb4d3cc228a4f819\mspmsnsv.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"tscuninstall"="c:\windows\system32\tscupgrd.exe" [2004-08-04 44544]
"MPlayer2_FixUp"="c:\windows\inf\unregmp2.exe" [2008-04-14 208896]
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Kodak EasyShare software.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Kodak EasyShare software.lnk
backup=c:\windows\pss\Kodak EasyShare software.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^WDDMStatus.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\WDDMStatus.lnk
backup=c:\windows\pss\WDDMStatus.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^Ryan^Start Menu^Programs^Startup^Picture Motion Browser Media Check Tool.lnk]
path=c:\documents and settings\Ryan\Start Menu\Programs\Startup\Picture Motion Browser Media Check Tool.lnk
backup=c:\windows\pss\Picture Motion Browser Media Check Tool.lnkStartup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UserFaultCheck]
c:\windows\system32\dumprep 0 -u [X]
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdaptecDirectCD]
2002-12-17 16:28 684032 —-a-w- c:\program files\Roxio\Easy CD Creator 5\DirectCD\Directcd.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2010-09-21 03:07 932288 —-a-r- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2011-01-31 08:44 35760 —-a-w- c:\program files\Adobe\Reader 9.0\Reader\reader_sl.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AGRSMMSG]
2004-06-29 13:06 88363 —-a-w- c:\windows\AGRSMMSG.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Alcmtr]
2005-04-12 05:10 65536 —-a-w- c:\windows\ALCMTR.EXE
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AlcWzrd]
2005-04-06 22:53 2805248 —-a-w- c:\windows\ALCWZRD.EXE
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
2008-04-14 00:12 15360 —-a-w- c:\windows\system32\ctfmon.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DivXUpdate]
2011-03-21 18:56 1230704 —-a-w- c:\program files\DivX\DivX Update\DivXUpdate.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DWQueuedReporting]
2007-03-22 23:29 39264 —-a-w- c:\progra~1\COMMON~1\MICROS~1\DW\DWTRIG20.EXE
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EKIJ5000StatusMonitor]
2008-10-22 11:54 1310720 —-a-w- c:\windows\system32\spool\drivers\w32x86\3\EKIJ5000MUI.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\igfxhkcmd]
2005-11-03 19:22 77824 —-a-w- c:\windows\system32\hkcmd.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\igfxpers]
2005-11-03 19:26 118784 —-a-w- c:\windows\system32\igfxpers.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\igfxtray]
2005-11-03 19:25 98304 —-a-w- c:\windows\system32\igfxtray.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2011-03-07 20:33 421160 —-a-w- c:\program files\iTunes\iTunesHelper.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2010-11-29 22:38 421888 —-a-w- c:\program files\QuickTime\QTTask.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RTHDCPL]
2005-04-13 03:21 14156800 —-a-w- c:\windows\RTHDCPL.EXE
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMan]
2005-04-06 22:57 90112 —-a-w- c:\windows\SOUNDMAN.EXE
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2010-05-14 15:44 248552 —-a-w- c:\program files\Common Files\Java\Java Update\jusched.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UfSeAgnt.exe]
2009-10-20 08:50 995528 —-a-w- c:\program files\Trend Micro\Internet Security\UfSeAgnt.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\TrendAntiVirus]
"DisableMonitoring"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
"DisableNotifications"= 1 (0x1)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Kodak\\Kodak EasyShare software\\bin\\EasyShare.exe"=
"c:\\Program Files\\eMule\\emule.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"9322:TCP"= 9322:TCP:EKDiscovery
"9323:TCP"= 9323:TCP:EKDiscovery
.
R2 Kodak AiO Network Discovery Service;Kodak AiO Network Discovery Service;c:\program files\Kodak\Printer\Center\EKDiscovery.exe [10/10/2008 12:33 PM 274432]
R2 KodakSvc;Kodak AiO Device Service;c:\program files\Kodak\Printer\Center\KodakSvc.exe [10/30/2008 10:58 AM 28672]
R2 tmpreflt;tmpreflt;c:\windows\system32\drivers\tmpreflt.sys [8/27/2010 4:07 PM 36432]
R2 WDDMService;WDDMService;c:\program files\Western Digital\WD SmartWare\WD Drive Manager\WDDMService.exe [3/9/2011 11:07 AM 238592]
R2 WDFME;WD File Management Engine;c:\program files\Western Digital\WD SmartWare\Front Parlor\WDFME\WDFME.exe [3/9/2011 11:18 AM 1060864]
R2 WDSC;WD File Management Shadow Engine;c:\program files\Western Digital\WD SmartWare\Front Parlor\WDSC.exe [3/9/2011 11:16 AM 484352]
S0 nkrinjkl;nkrinjkl;c:\windows\system32\drivers\twhxykwd.sys –> c:\windows\system32\drivers\twhxykwd.sys [?]
S0 qugd;qugd;c:\windows\system32\drivers\yfojj.sys –> c:\windows\system32\drivers\yfojj.sys [?]
S2 tmevtmgr;tmevtmgr;c:\windows\system32\drivers\tmevtmgr.sys [8/27/2010 4:10 PM 50256]
S2 TmProxy;Trend Micro Proxy Service;c:\program files\Trend Micro\Internet Security\TmProxy.exe [8/27/2010 4:10 PM 677128]
S3 ivusb;Initio Driver for USB Default Controller;c:\windows\system32\DRIVERS\ivusb.sys –> c:\windows\system32\DRIVERS\ivusb.sys [?]
S3 Normandy;Normandy SR2; [x]
S3 WDC_SAM;WD SCSI Pass Thru driver;c:\windows\system32\drivers\wdcsam.sys [9/2/2010 12:45 PM 11520]
.
.
——- Supplementary Scan ——-
.
uInternet Settings,ProxyOverride = *.local
DPF: DirectAnimation Java Classes - file://c:\windows\Java\classes\dajava.cab
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-05-15 11:36
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10p_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10p_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
——————— DLLs Loaded Under Running Processes ———————
.
- - - - - - - > 'winlogon.exe'(816)
c:\windows\system32\igfxdev.dll
.
Completion time: 2011-05-15 11:39:28
ComboFix-quarantined-files.txt 2011-05-15 15:39
ComboFix2.txt 2011-04-16 05:12
.
Pre-Run: 136,199,106,560 bytes free
Post-Run: 136,376,999,936 bytes free
.
- - End Of File - - 6C396223FCE09A9C580B3566794ED04F
In case you were wondering…. here is my rkill log This log file is located at C:\rkill.log. Please post this only if requested to by the person helping you. Otherwise you can close this log when you wish. Rkill was run on 05/14/2011 at 7:53:07. Operating System: Microsoft Windows XP Processes terminated by Rkill or while it was running: C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe C:\Documents and Settings\All Users\Application Data\YnrYgeoYrpuFD.exe C:\WINDOWS\System32\attrib.exe C:\WINDOWS\System32\attrib.exe C:\Documents and Settings\All Users\Application Data\16375588.exe ce.exe Rkill completed on 05/14/2011 at 7:56:25.

Where would the MBAM log file be located on my computer?

The log should be found here: C:\Documents and Settings\Username\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\log-date.txt
Here are the three logs that I ran from 5/13 - 5/14: Malwarebytes' Anti-Malware 1.50.1.1100 www.malwarebytes.org Database version: 6371 Windows 5.1.2600 Service Pack 1 Internet Explorer 6.0.2800.1106 5/13/2011 4:19:37 PM mbam-log-2011-05-13 (16-19-37).txt Scan type: Quick scan Objects scanned: 171191 Time elapsed: 5 minute(s), 50 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 1 Folders Infected: 0 Files Infected: 1 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\ActiveDesktop\NoChangingWallPaper (PUM.Hijack.DisplayProperties) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully. Folders Infected: (No malicious items detected) Files Infected: c:\documents and settings\all users\application data\16375588.exe (Trojan.FakeAlert.Gen) -> Quarantined and deleted successfully. Malwarebytes' Anti-Malware 1.50.1.1100 www.malwarebytes.org Database version: 6371 Windows 5.1.2600 Service Pack 1 Internet Explorer 6.0.2800.1106 5/14/2011 8:07:03 AM mbam-log-2011-05-14 (08-07-03).txt Scan type: Quick scan Objects scanned: 171307 Time elapsed: 5 minute(s), 21 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected) Malwarebytes' Anti-Malware 1.50.1.1100 www.malwarebytes.org Database version: 6576 Windows 5.1.2600 Service Pack 1 Internet Explorer 6.0.2800.1106 5/14/2011 8:20:34 AM mbam-log-2011-05-14 (08-20-34).txt Scan type: Quick scan Objects scanned: 168335 Time elapsed: 5 minute(s), 15 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected)
Hi again,

Emule

Above listed ones are P2P file sharing programs. P2P downloads are nowadays one of those things that most likely bring infection into the system. My recommendation is to uninstall these (and other if present) P2P file sharing programs.


Open notepad and copy/paste the text in the quotebox below into it:

Driver::
nkrinjkl
qugd
File::
c:\windows\system32\drivers\twhxykwd.sys
c:\windows\system32\drivers\yfojj.sys
Registry::
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UserFaultCheck]


Save this as
CFScript

A word of warning: Neither I nor sUBs are responsible for any damage you may have caused your machine. This tool is not a toy and not for everyday use.

[external image: Posted Image]

Close all browser windows and refering to the picture above, drag CFScript into ComboFix.exe
Then post the resultant log.



Your Java is out of date. Older versions have vulnerabilities that malware can use to infect your system. Please follow these steps to remove older version Java components and update to the latest version…

Updating Java:
  • Download the latest version of Java Runtime Environment (JRE) 6 Update 25.
  • Click the
    Download
    button to the right.
  • Select Windows on platform combobox and check the box that says:
    Accept License Agreement. Click continue.
  • The page will refresh.
  • Click on the link to download Windows Offline Installation with or without Multi-language and save to your desktop.
  • Close any programs you may have running - especially your web browser.
  • Go to Start > Control Panel double-click on Add/Remove programs and remove all older versions of Java.
  • Check any item with Java Runtime Environment (JRE or J2SE) in the name.
  • Click the Remove or Change/Remove button.
  • Repeat as many times as necessary to remove each Java versions.
  • Reboot your computer once all Java components are removed.
  • Then from your desktop double-click on jre-6u25-windows-i586-p.exe to install the newest version. Uncheck Carbonite online backup trial if it's offered there.


* Go here to run an online scanner from ESET.
  • Note: You will need to use Internet explorer for this scan
  • Tick the box next to YES, I accept the Terms of Use.
  • Click Start
  • When asked, allow the activex control to install
  • Click Start
  • Make sure that the option Remove found threats is UNchecked..
  • Click Scan
  • Wait for the scan to finish.


Post back its report, a fresh dds.txt log and above mentioned ComboFix resultant log.

After that re-download & run Unhide tool.
ComboFix 11-05-14.03 - Ryan 05/15/2011 12:45:54.4.2 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1015.459 [GMT -4:00]
Running from: c:\documents and settings\[removed]\Desktop\iexplore2.exe
Command switches used :: c:\documents and settings\Ryan\Desktop\CFScript.txt
AV: Trend Micro AntiVirus *Disabled/Updated* {7D2296BC-32CC-4519-917E-52E652474AF5}
.
FILE ::
"c:\windows\system32\drivers\twhxykwd.sys"
"c:\windows\system32\drivers\yfojj.sys"
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
——-\Service_nkrinjkl
——-\Service_qugd
.
.
((((((((((((((((((((((((( Files Created from 2011-04-15 to 2011-05-15 )))))))))))))))))))))))))))))))
.
.
2011-05-15 11:37 . 2009-08-06 23:23 274288 —-a-w- c:\windows\system32\mucltui.dll
2011-05-15 01:19 . 2009-07-27 23:17 135168 -c—-w- c:\windows\system32\dllcache\shsvcs.dll
2011-05-15 01:18 . 2010-11-02 15:17 40960 -c—-w- c:\windows\system32\dllcache\ndproxy.sys
2011-05-15 01:17 . 2010-10-11 14:59 45568 -c—-w- c:\windows\system32\dllcache\wab.exe
2011-05-15 01:17 . 2011-02-08 13:33 978944 -c—-w- c:\windows\system32\dllcache\mfc42.dll
2011-05-15 01:17 . 2010-09-18 06:53 953856 -c—-w- c:\windows\system32\dllcache\mfc40u.dll
2011-05-15 01:17 . 2010-08-23 16:12 617472 -c—-w- c:\windows\system32\dllcache\comctl32.dll
2011-05-14 16:43 . 2011-02-22 23:06 12800 -c—-w- c:\windows\system32\dllcache\xpshims.dll
2011-05-14 16:43 . 2011-02-22 23:06 602112 -c—-w- c:\windows\system32\dllcache\msfeeds.dll
2011-05-14 16:43 . 2011-02-22 23:06 55296 -c—-w- c:\windows\system32\dllcache\msfeedsbs.dll
2011-05-14 16:43 . 2011-02-22 23:06 743424 -c—-w- c:\windows\system32\dllcache\iedvtool.dll
2011-05-14 16:43 . 2011-02-22 23:06 247808 -c—-w- c:\windows\system32\dllcache\ieproxy.dll
2011-05-14 16:43 . 2011-02-22 23:06 1991680 -c—-w- c:\windows\system32\dllcache\iertutil.dll
2011-05-14 16:43 . 2011-02-22 23:06 11080704 -c—-w- c:\windows\system32\dllcache\ieframe.dll
2011-05-14 16:29 . 2009-07-31 14:05 1372672 -c—-w- c:\windows\system32\dllcache\msxml6.dll
2011-05-14 16:29 . 2008-04-13 17:27 79872 -c—-w- c:\windows\system32\dllcache\msxml6r.dll
2011-05-14 16:28 . 2008-04-14 00:11 81920 ——w- c:\windows\system32\ieencode.dll
2011-05-14 16:28 . 2006-12-28 19:01 19569 —-a-w- c:\windows\005981_.tmp
2011-05-14 15:57 . 2011-05-14 15:57 ——– d—–w- c:\program files\MSXML 6.0
2011-05-14 15:40 . 2011-02-17 13:18 455936 -c—-w- c:\windows\system32\dllcache\mrxsmb.sys
2011-05-14 15:40 . 2010-06-18 13:36 3558912 -c—-w- c:\windows\system32\dllcache\moviemk.exe
2011-05-14 15:39 . 2011-02-17 13:18 357888 -c—-w- c:\windows\system32\dllcache\srv.sys
2011-05-14 15:38 . 2010-08-27 08:02 119808 -c—-w- c:\windows\system32\dllcache\t2embed.dll
2011-05-14 15:38 . 2009-10-15 16:28 81920 -c—-w- c:\windows\system32\dllcache\fontsub.dll
2011-05-14 15:38 . 2009-11-21 15:51 471552 -c—-w- c:\windows\system32\dllcache\aclayers.dll
2011-05-14 15:34 . 2009-06-21 22:04 153088 -c—-w- c:\windows\system32\dllcache\triedit.dll
2011-05-14 15:32 . 2009-06-10 13:19 2066432 -c—-w- c:\windows\system32\dllcache\mstscax.dll
2011-05-14 15:30 . 2009-03-06 14:22 284160 -c—-w- c:\windows\system32\dllcache\pdh.dll
2011-05-14 15:30 . 2009-02-09 12:10 473600 -c—-w- c:\windows\system32\dllcache\fastprox.dll
2011-05-14 15:30 . 2009-02-09 12:10 401408 -c—-w- c:\windows\system32\dllcache\rpcss.dll
2011-05-14 15:30 . 2009-02-06 11:11 110592 -c—-w- c:\windows\system32\dllcache\services.exe
2011-05-14 15:30 . 2010-12-20 17:26 730112 -c—-w- c:\windows\system32\dllcache\lsasrv.dll
2011-05-14 15:30 . 2010-12-09 15:15 718336 -c—-w- c:\windows\system32\dllcache\ntdll.dll
2011-05-14 15:30 . 2009-02-09 12:10 617472 -c—-w- c:\windows\system32\dllcache\advapi32.dll
2011-05-14 15:30 . 2009-02-09 12:10 453120 -c—-w- c:\windows\system32\dllcache\wmiprvsd.dll
2011-05-14 15:30 . 2009-02-06 10:10 227840 -c—-w- c:\windows\system32\dllcache\wmiprvse.exe
2011-05-14 15:30 . 2010-12-09 13:42 2148864 -c—-w- c:\windows\system32\dllcache\ntkrnlmp.exe
2011-05-14 15:30 . 2010-12-09 13:38 2192768 -c—-w- c:\windows\system32\dllcache\ntoskrnl.exe
2011-05-14 15:30 . 2010-12-09 13:07 2027008 -c—-w- c:\windows\system32\dllcache\ntkrpamp.exe
2011-05-14 15:28 . 2008-10-15 16:34 337408 -c—-w- c:\windows\system32\dllcache\netapi32.dll
2011-05-14 15:28 . 2008-05-01 14:33 331776 -c—-w- c:\windows\system32\dllcache\msadce.dll
2011-05-14 15:27 . 2008-05-08 14:02 203136 -c—-w- c:\windows\system32\dllcache\rmcast.sys
2011-05-14 13:26 . 2008-04-14 00:11 1082368 —-a-w- c:\windows\system32\esent.dll
2011-05-14 13:00 . 2009-08-25 09:17 354816 —-a-w- c:\windows\system32\winhttp.dll
2011-05-14 13:00 . 2008-04-14 00:12 18944 —-a-w- c:\windows\system32\qmgrprxy.dll
2011-05-13 20:10 . 2009-08-06 23:24 217816 —-a-w- c:\windows\system32\wuaucpl.cpl
2011-05-13 20:06 . 2005-11-03 19:21 135168 —-a-w- c:\windows\system32\igfxres.dll
2011-05-13 18:24 . 2002-09-03 16:25 98304 -c–a-w- c:\windows\system32\dllcache\msir3jp.dll
2011-05-13 18:23 . 2002-09-03 16:29 18944 -c–a-w- c:\windows\system32\dllcache\cprofile.exe
2011-05-13 18:21 . 2008-04-14 00:12 45568 —-a-w- c:\windows\system32\safrslv.dll
2011-05-13 18:20 . 2008-04-14 00:12 281088 —-a-w- c:\program files\Windows NT\Pinball\pinball.exe
2011-05-13 18:19 . 2009-02-09 12:10 453120 —-a-w- c:\windows\system32\wbem\wmiprvsd.dll
2011-05-13 18:18 . 2008-04-13 18:40 57600 —-a-w- c:\windows\system32\drivers\redbook.sys
2011-05-13 18:18 . 2004-08-04 05:31 20992 —-a-w- c:\windows\system32\drivers\rtl8139.sys
2011-05-13 18:18 . 2008-04-14 00:12 129536 —-a-w- c:\windows\system32\ksproxy.ax
2011-05-13 18:18 . 2008-04-14 00:11 4096 —-a-w- c:\windows\system32\ksuser.dll
2011-05-13 18:17 . 2008-04-14 00:13 40840 —-a-w- c:\windows\system32\drivers\termdd.sys
2011-05-13 18:17 . 2008-04-14 00:12 741376 —-a-w- c:\program files\Common Files\Microsoft Shared\Speech\sapi.dll
2011-05-13 18:17 . 2008-04-14 00:12 146432 —-a-w- c:\windows\system\winspool.drv
2011-05-13 18:17 . 2008-04-13 18:54 11264 —-a-w- c:\windows\system32\drivers\irenum.sys
2011-05-13 18:17 . 2002-09-03 17:04 24661 -c–a-w- c:\windows\system32\dllcache\spxcoins.dll
2011-05-13 18:17 . 2002-09-03 17:04 24661 —-a-w- c:\windows\system32\spxcoins.dll
2011-05-13 18:17 . 2002-09-03 16:35 13312 -c–a-w- c:\windows\system32\dllcache\irclass.dll
2011-05-13 18:17 . 2002-09-03 16:35 13312 —-a-w- c:\windows\system32\irclass.dll
2011-05-13 18:17 . 2008-04-14 00:12 74752 —-a-w- c:\windows\system32\storprop.dll
2011-05-13 18:16 . 2002-09-03 17:16 7046 —-a-r- c:\windows\SET102.tmp
2011-05-13 18:16 . 2002-09-03 16:35 13608 —-a-r- c:\windows\SETE4.tmp
2011-05-13 18:16 . 2002-09-03 16:50 1086182 —-a-r- c:\windows\SETCF.tmp
2011-05-13 14:21 . 2011-05-13 20:58 ——– d—–w- c:\documents and settings\Administrator
2011-05-12 00:34 . 2011-05-14 15:21 ——– d—–w- c:\windows\system32\wbem\Repository
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-03-04 06:37 . 2002-09-03 17:09 420864 —-a-w- c:\windows\system32\vbscript.dll
2011-03-03 13:21 . 2002-09-03 17:11 1857920 —-a-w- c:\windows\system32\win32k.sys
2011-02-22 23:06 . 2002-09-03 16:39 43520 —-a-w- c:\windows\system32\licmgr10.dll
2011-02-22 23:06 . 2002-09-03 16:35 1469440 ——w- c:\windows\system32\inetcpl.cpl
2011-02-22 11:41 . 2004-08-04 05:59 385024 —-a-w- c:\windows\system32\html.iec
2011-02-18 21:36 . 2010-08-28 22:23 41984 —-a-w- c:\windows\system32\drivers\usbaapl.sys
2011-02-18 21:36 . 2010-08-28 22:23 4184352 —-a-w- c:\windows\system32\usbaaplrc.dll
2011-02-17 13:18 . 2002-09-03 16:42 455936 —-a-w- c:\windows\system32\drivers\mrxsmb.sys
2011-02-17 13:18 . 2002-09-03 17:04 357888 —-a-w- c:\windows\system32\drivers\srv.sys
2011-02-17 12:32 . 2010-08-27 18:28 5120 —-a-w- c:\windows\system32\xpsp4res.dll
2011-02-16 20:52 . 2010-09-02 16:45 11520 —-a-w- c:\windows\system32\drivers\wdcsam.sys
2011-02-15 12:56 . 2002-09-03 16:27 290432 —-a-w- c:\windows\system32\atmfd.dll
.
.
——- Sigcheck ——-
.
[-] 2009-01-31 00:33 . 051B1BDECD6DEE18C771B5D5EC7F044D . 27136 . . [11.0.5721.5262] . . c:\windows\ERDNT\cache\mspmsnsv.dll
[-] 2009-01-31 00:33 . 051B1BDECD6DEE18C771B5D5EC7F044D . 27136 . . [11.0.5721.5262] . . c:\windows\system32\mspmsnsv.dll
[7] 2008-04-14 00:12 . C7E39EA41233E9F5B86C8DA3A9F1E4A8 . 52224 . . [9.0.1.56] . . c:\windows\$NtUninstallWMFDist11$\mspmsnsv.dll
[7] 2004-08-04 07:56 . C086483E3DBA8C1C0A687EC8D5B3D4C1 . 52224 . . [9.0.1.56] . . c:\windows\ServicePackFiles\i386\mspmsnsv.dll
[7] 2004-08-04 07:56 . C086483E3DBA8C1C0A687EC8D5B3D4C1 . 52224 . . [9.0.1.56] . . c:\windows\SoftwareDistribution\Download\16b2c96a0c41f4dfdb4d3cc228a4f819\mspmsnsv.dll
.
((((((((((((((((((((((((((((( SnapShot@2011-05-15_15.36.26 )))))))))))))))))))))))))))))))))))))))))
.
+ 2011-05-15 16:56 . 2011-05-15 16:56 16384 c:\windows\temp\Perflib_Perfdata_200.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"tscuninstall"="c:\windows\system32\tscupgrd.exe" [2004-08-04 44544]
"MPlayer2_FixUp"="c:\windows\inf\unregmp2.exe" [2008-04-14 208896]
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Kodak EasyShare software.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Kodak EasyShare software.lnk
backup=c:\windows\pss\Kodak EasyShare software.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^WDDMStatus.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\WDDMStatus.lnk
backup=c:\windows\pss\WDDMStatus.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^Ryan^Start Menu^Programs^Startup^Picture Motion Browser Media Check Tool.lnk]
path=c:\documents and settings\Ryan\Start Menu\Programs\Startup\Picture Motion Browser Media Check Tool.lnk
backup=c:\windows\pss\Picture Motion Browser Media Check Tool.lnkStartup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdaptecDirectCD]
2002-12-17 16:28 684032 —-a-w- c:\program files\Roxio\Easy CD Creator 5\DirectCD\Directcd.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2010-09-21 03:07 932288 —-a-r- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2011-01-31 08:44 35760 —-a-w- c:\program files\Adobe\Reader 9.0\Reader\reader_sl.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AGRSMMSG]
2004-06-29 13:06 88363 —-a-w- c:\windows\AGRSMMSG.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Alcmtr]
2005-04-12 05:10 65536 —-a-w- c:\windows\ALCMTR.EXE
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AlcWzrd]
2005-04-06 22:53 2805248 —-a-w- c:\windows\ALCWZRD.EXE
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
2008-04-14 00:12 15360 —-a-w- c:\windows\system32\ctfmon.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DivXUpdate]
2011-03-21 18:56 1230704 —-a-w- c:\program files\DivX\DivX Update\DivXUpdate.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DWQueuedReporting]
2007-03-22 23:29 39264 —-a-w- c:\progra~1\COMMON~1\MICROS~1\DW\DWTRIG20.EXE
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EKIJ5000StatusMonitor]
2008-10-22 11:54 1310720 —-a-w- c:\windows\system32\spool\drivers\w32x86\3\EKIJ5000MUI.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\igfxhkcmd]
2005-11-03 19:22 77824 —-a-w- c:\windows\system32\hkcmd.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\igfxpers]
2005-11-03 19:26 118784 —-a-w- c:\windows\system32\igfxpers.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\igfxtray]
2005-11-03 19:25 98304 —-a-w- c:\windows\system32\igfxtray.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2011-03-07 20:33 421160 —-a-w- c:\program files\iTunes\iTunesHelper.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2010-11-29 22:38 421888 —-a-w- c:\program files\QuickTime\QTTask.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RTHDCPL]
2005-04-13 03:21 14156800 —-a-w- c:\windows\RTHDCPL.EXE
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMan]
2005-04-06 22:57 90112 —-a-w- c:\windows\SOUNDMAN.EXE
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2010-05-14 15:44 248552 —-a-w- c:\program files\Common Files\Java\Java Update\jusched.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UfSeAgnt.exe]
2009-10-20 08:50 995528 —-a-w- c:\program files\Trend Micro\Internet Security\UfSeAgnt.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\TrendAntiVirus]
"DisableMonitoring"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
"DisableNotifications"= 1 (0x1)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Kodak\\Kodak EasyShare software\\bin\\EasyShare.exe"=
"c:\\Program Files\\eMule\\emule.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"9322:TCP"= 9322:TCP:EKDiscovery
"9323:TCP"= 9323:TCP:EKDiscovery
.
R2 Kodak AiO Network Discovery Service;Kodak AiO Network Discovery Service;c:\program files\Kodak\Printer\Center\EKDiscovery.exe [10/10/2008 12:33 PM 274432]
R2 KodakSvc;Kodak AiO Device Service;c:\program files\Kodak\Printer\Center\KodakSvc.exe [10/30/2008 10:58 AM 28672]
R2 tmpreflt;tmpreflt;c:\windows\system32\drivers\tmpreflt.sys [8/27/2010 4:07 PM 36432]
R2 WDDMService;WDDMService;c:\program files\Western Digital\WD SmartWare\WD Drive Manager\WDDMService.exe [3/9/2011 11:07 AM 238592]
R2 WDFME;WD File Management Engine;c:\program files\Western Digital\WD SmartWare\Front Parlor\WDFME\WDFME.exe [3/9/2011 11:18 AM 1060864]
R2 WDSC;WD File Management Shadow Engine;c:\program files\Western Digital\WD SmartWare\Front Parlor\WDSC.exe [3/9/2011 11:16 AM 484352]
S2 tmevtmgr;tmevtmgr;c:\windows\system32\drivers\tmevtmgr.sys [8/27/2010 4:10 PM 50256]
S2 TmProxy;Trend Micro Proxy Service;c:\program files\Trend Micro\Internet Security\TmProxy.exe [8/27/2010 4:10 PM 677128]
S3 ivusb;Initio Driver for USB Default Controller;c:\windows\system32\DRIVERS\ivusb.sys –> c:\windows\system32\DRIVERS\ivusb.sys [?]
S3 Normandy;Normandy SR2; [x]
S3 WDC_SAM;WD SCSI Pass Thru driver;c:\windows\system32\drivers\wdcsam.sys [9/2/2010 12:45 PM 11520]
.
.
——- Supplementary Scan ——-
.
uInternet Settings,ProxyOverride = *.local
DPF: DirectAnimation Java Classes - file://c:\windows\Java\classes\dajava.cab
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-05-15 12:57
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10p_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10p_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
——————— DLLs Loaded Under Running Processes ———————
.
- - - - - - - > 'explorer.exe'(1880)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
———————— Other Running Processes ————————
.
c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Juniper Networks\Common Files\dsNcService.exe
c:\program files\Java\jre6\bin\jqs.exe
.
**************************************************************************
.
Completion time: 2011-05-15 13:02:07 - machine was rebooted
ComboFix-quarantined-files.txt 2011-05-15 17:02
ComboFix2.txt 2011-05-15 15:39
ComboFix3.txt 2011-04-16 05:12
.
Pre-Run: 136,360,652,800 bytes free
Post-Run: 136,327,073,792 bytes free
.
- - End Of File - - B346EB3A1A06D21835666A10DDA2B568
I updated JAVA, but when I try to run the ESET scan (after accepting and hitting start, before accepting the active x)…my internet explorer browsers shut down. FYI: My anti-virus is shut off too.,
I did run the ESET after a reboot and the same thing also happens. I did run unhide, but my start menu program folders are still mostly empty.
Hi,

I did run unhide, but my start menu program folders are still mostly empty.

Please try the version linked in my previous post.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI