This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Baseline

4 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Evening,
Using Google Chrome and every time I search with Google, it redirects me. Please help me if possible. I am placing my Hijackthis log below. Thanks for any assistance!


Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 6:48:02 PM, on 9/29/2011
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\acs.exe
C:\Program Files\COMODO\COMODO Internet Security\cfp.exe
C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
C:\WINDOWS\system32\M-AudioTaskBarIcon.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\McAfee Security Scan\2.0.181\SSScheduler.exe
C:\Program Files\NETGEAR\WNA1100\WNA1100.exe
C:\Program Files\Philips\GoGear VIBE Device Manager\GoGear_Vibe_DeviceManager.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ArcCon.ac
C:\Program Files\NETGEAR\WNA1100\WifiSvc.exe
C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe
C:\PROGRA~1\Yahoo!\Messenger\ymsgr_tray.exe
C:\Documents and Settings\Courtney\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Courtney\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Courtney\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Courtney\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Courtney\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Courtney\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\WINDOWS\system32\notepad.exe
C:\Documents and Settings\Courtney\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Courtney\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Program Files\Trend Micro\HiJackThis\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
R3 - URLSearchHook: BitTorrentBar Toolbar - {88c7f2aa-f93f-432c-8f0e-b7d85967a527} - C:\Program Files\BitTorrentBar\prxtbBit2.dll
R3 - URLSearchHook: (no name) - - (no file)
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
O2 - BHO: IEPlugin Class - {11222041-111B-46E3-BD29-EFB2449479B1} - C:\PROGRA~1\ArcSoft\MEDIAC~1\INTERN~1\ARCURL~1.DLL
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Conduit Engine - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files\ConduitEngine\prxConduitEngine.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL
O2 - BHO: BitTorrentBar - {88c7f2aa-f93f-432c-8f0e-b7d85967a527} - C:\Program Files\BitTorrentBar\prxtbBit2.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\YTSingleInstance.dll
O3 - Toolbar: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
O3 - Toolbar: BitTorrentBar Toolbar - {88c7f2aa-f93f-432c-8f0e-b7d85967a527} - C:\Program Files\BitTorrentBar\prxtbBit2.dll
O3 - Toolbar: Conduit Engine - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files\ConduitEngine\prxConduitEngine.dll
O4 - HKLM\..\Run: [COMODO Internet Security] "C:\Program Files\COMODO\COMODO Internet Security\cfp.exe" -h
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [ArcSoft Connection Service] C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
O4 - HKLM\..\Run: [M-Audio Taskbar Icon] C:\WINDOWS\system32\M-AudioTaskBarIcon.exe
O4 - HKLM\..\Run: [jswtrayutil] "C:\Program Files\NETGEAR\WNA1100\jswtrayutil.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Messenger (Yahoo!)] "C:\PROGRA~1\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\Courtney\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [EA Core] "C:\Program Files\Electronic Arts\EADM\Core.exe" -silent
O4 - HKUS\S-1-5-18\..\Run: [79d239a3-2e0f-4fad-8301-bd51de1a77ab_8] "C:\WINDOWS\system32\rundll32.exe" "C:\Documents and Settings\Courtney\Application Data\79d239a3-2e0f-4fad-8301-bd51de1a77ab_8.avi", start minimized (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [79d239a3-2e0f-4fad-8301-bd51de1a77ab_8] "C:\WINDOWS\system32\rundll32.exe" "C:\Documents and Settings\Courtney\Application Data\79d239a3-2e0f-4fad-8301-bd51de1a77ab_8.avi", start minimized (User 'Default user')
O4 - Global Startup: McAfee Security Scan Plus.lnk = ?
O4 - Global Startup: NETGEAR WNA1100 Smart Wizard.lnk = ?
O4 - Global Startup: Philips GoGear VIBE Device Manager.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Google Sidewiki… - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.com/download.yahoo.com/…nst_current.cab
O16 - DPF: {73ECB3AA-4717-450C-A2AB-D00DAD9EE203} (GMNRev Class) - http://h20270.www2.hp.com/ediags/gmn2/inst…tDetection2.cab
O16 - DPF: {A084A130-28AE-4B32-B51A-1C8CE164BC88} (WNICheck2 Class) - http://www.convergysworkathome.com/AppHardT.CAB
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL
O20 - AppInit_DLLs: C:\WINDOWS\System32\catsrvut32.dll C:\WINDOWS\system32\guard32.dll
O20 - Winlogon Notify: 14390e54741 - C:\WINDOWS\System32\catsrvut32.dll (file missing)
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: ArcSoft Connect Daemon (ACDaemon) - ArcSoft Inc. - C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
O23 - Service: Atheros Configuration Service (ACS) - Atheros - C:\WINDOWS\system32\acs.exe
O23 - Service: COMODO Internet Security Helper Service (cmdAgent) - COMODO - C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: JumpStart Wi-Fi Protected Setup (jswpsapi) - Atheros Communications, Inc. - C:\Program Files\NETGEAR\WNA1100\jswpsapi.exe
O23 - Service: McAfee Security Scan Component Host Service (McComponentHostService) - McAfee, Inc. - C:\Program Files\McAfee Security Scan\2.0.181\McCHSvc.exe
O23 - Service: WSWNA1100 - Unknown owner - C:\Program Files\NETGEAR\WNA1100\WifiSvc.exe
O23 - Service: Yahoo! Updater (YahooAUService) - Yahoo! Inc. - C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe

–
End of file - 10091 bytes
Hello and welcome to What The Tech.

I am currently assessing your situation and will be back with a fix for your problem as soon as possible.

Please subscribe to this thread to get immediate notification of replies as soon as they are posted. To do this, click Options, then click Track this topic. Please select Immediate Email Notification for the topic subscription, then click Proceed.

Please be patient with me during this time.

Meanwhile, please make a reply to this topic to acknowledge that you have read this and is still with me to tackle the problem until the end. If I do not get any response within 3 days, this topic will be closed.
Hello cc78233 :),

Welcome to What The Tech. I am Jack&Jill, and I will be helping you out.

Before we go further, there are a few things that I would like to make clear so that we are share the same understanding.
  • Please observe and follow these Terms of Use and the rules in Are you Infected? Getting Started: How To Get Help.
  • Any advice is for your computer only and is taken at your own risk. Fixes sometimes will cause unexpected results, but I will do my best to assist you.
  • Please read the instructions carefully and follow them closely, in the order they are presented to you.
  • If you have any doubts or problems during the fix, please stop and ask.
  • All the tools that I will ask you to download and use are safe. Please allow if prompted by any of your security softwares.
  • Do not use or run any malware cleaning tools without supervision as they may cause more harm if improperly used.
  • Refrain from installing any new programs except those that I request during the fix to prevent interference to my diagnosis of the problem.
  • Lack of malware symptoms does not mean your computer is clean. Stick to this topic until I give the All Clear.
  • If you do not reply within 3 days, this topic will be closed.
If you are agreeable to the above, then everything should go smoothly :) . We may begin.

——————–

Please download DDS from one of the links below and save it to your desktop.

Link 1
Link 2
Link 3

Please disable any script blocker before running DDS.

  • Double click on the dds file and a command window will appear. This is normal.
  • Shortly after, two logs will appear:
    • DDS.txt
    • Attach.txt
  • A window will open instructing you to save and post the logs.
  • Save the logs to a convenient location such as your desktop.
  • Copy the contents of both logs and post them in your next reply.
——————–

Please download aswMBR and save it to your desktop. Click here.
  • Please disable your real time protection of any Antivirus, Antispyware or Antimalware programs temporarily. They will interfere and may cause unexpected results.
  • If you need help to disable your protection programs see here and here.
  • Double click the aswMBR.exe file to run it. If you are asked to download an antivirus software, please allow.
  • Click on the Scan button to start. The program will launch a scan.
  • When done, you will see Scan finished successfully. Please click on Save log and save the file to your desktop.
  • Please post the contents of the log in your next reply.
——————–

Please post back:
1. DDS logs (DDS.txt and Attach.txt)
2. aswMBR log
Hello cc78233 :), I usually close the topic after 3 days without any reply, and it has already been 2 days since my last post. Do you still need help? Any problems following my instructions? Need more time? If I do not get any response within the next 24 hours, this topic will be closed.
Hi! Yes I still need assistance. Actually I was in the process of running the log, my computer froze. The windows finally closed, but now everytime I click on an icon, nothing happens. I am pretty sure this is a different issue, but I will restart my computer and restart the process. Thanks for your help again.
.
DDS (Ver_2011-08-26.01) - NTFSx86
Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_26
Run by [removed] at 20:30:28 on 2011-10-03
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.895.273 [GMT -5:00]
.
AV: COMODO Antivirus *Enabled/Outdated* {043803A5-4F86-4ef7-AFC5-F6E02A79969B}
FW: CA Personal Firewall *Enabled*
FW: COMODO Firewall *Enabled*
.
============== Running Processes ===============
.
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
C:\WINDOWS\system32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup
svchost.exe
C:\WINDOWS\Explorer.EXE
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\acs.exe
svchost.exe
C:\Program Files\COMODO\COMODO Internet Security\cfp.exe
C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
C:\WINDOWS\system32\M-AudioTaskBarIcon.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\McAfee Security Scan\2.0.181\SSScheduler.exe
C:\Program Files\NETGEAR\WNA1100\WNA1100.exe
C:\Program Files\Philips\GoGear VIBE Device Manager\GoGear_Vibe_DeviceManager.exe
C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\NETGEAR\WNA1100\WifiSvc.exe
C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe
C:\PROGRA~1\Yahoo!\Messenger\ymsgr_tray.exe
C:\Documents and Settings\Courtney\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Courtney\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Courtney\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Courtney\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Courtney\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Courtney\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Courtney\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Courtney\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Courtney\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.yahoo.com
uSearch Page =
uSearch Bar =
mDefault_Page_URL = hxxp://www.yahoo.com
mStart Page = hxxp://www.yahoo.com
uInternet Settings,ProxyOverride =
mSearchAssistant =
uURLSearchHooks: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program

files\yahoo!\companion\installs\cpn1\yt.dll
uURLSearchHooks: BitTorrentBar Toolbar: {88c7f2aa-f93f-432c-8f0e-b7d85967a527} - c:\program

files\bittorrentbar\prxtbBit0.dll
uURLSearchHooks: H - No File
BHO: &Yahoo! Toolbar Helper: {02478d38-c3f9-4efb-9b51-7695eca05670} - c:\program

files\yahoo!\companion\installs\cpn1\yt.dll
BHO: IEPlugin Class: {11222041-111b-46e3-bd29-efb2449479b1} - c:\progra~1\arcsoft\mediac~1\intern~1\ARCURL~1.DLL
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common

files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} -

c:\progra~1\micros~2\office12\GRA8E1~1.DLL
BHO: BitTorrentBar Toolbar: {88c7f2aa-f93f-432c-8f0e-b7d85967a527} - c:\program files\bittorrentbar\prxtbBit0.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program

files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
BHO: SingleInstance Class: {fdad4da1-61a2-4fd8-9c17-86f7ac245081} - c:\program

files\yahoo!\companion\installs\cpn1\YTSingleInstance.dll
TB: {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No File
TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn1\yt.dll
TB: BitTorrentBar Toolbar: {88c7f2aa-f93f-432c-8f0e-b7d85967a527} - c:\program files\bittorrentbar\prxtbBit0.dll
TB: {D4027C7F-154A-4066-A1AD-4243D8127440} - No File
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [Messenger (Yahoo!)] "c:\progra~1\yahoo!\messenger\YahooMessenger.exe" -quiet
uRun: [Google Update] "c:\documents and settings\courtney\local settings\application

data\google\update\GoogleUpdate.exe" /c
uRun: [EA Core] "c:\program files\electronic arts\eadm\Core.exe" -silent
mRun: [COMODO Internet Security] "c:\program files\comodo\comodo internet security\cfp.exe" -h
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
mRun: [ArcSoft Connection Service] c:\program files\common files\arcsoft\connection service\bin\ACDaemon.exe
mRun: [M-Audio Taskbar Icon] c:\windows\system32\M-AudioTaskBarIcon.exe
mRun: [jswtrayutil] "c:\program files\netgear\wna1100\jswtrayutil.exe"
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
dRun: [79d239a3-2e0f-4fad-8301-bd51de1a77ab_8] "c:\windows\system32\rundll32.exe" "c:\documents and

settings\courtney\application data\79d239a3-2e0f-4fad-8301-bd51de1a77ab_8.avi", start minimized
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\mcafee~1.lnk - c:\program files\mcafee security

scan\2.0.181\SSScheduler.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\netgea~1.lnk - c:\program

files\netgear\wna1100\WNA1100.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\philip~1.lnk - c:\program files\philips\gogear vibe

device manager\GoGear_Vibe_DeviceManager.exe
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000
IE: Google Sidewiki… - c:\program files\google\google

toolbar\component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} -

c:\progra~1\micros~2\office12\ONBttnIE.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} -

c:\progra~1\micros~2\office12\REFIEBAR.DLL
DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} -

hxxp://us.dl1.yimg.com/download.yahoo.com/dl/yinst/yinst_current.cab
DPF: {73ECB3AA-4717-450C-A2AB-D00DAD9EE203} -

hxxp://h20270.www2.hp.com/ediags/gmn2/install/HPProductDetection2.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} -

hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab
DPF: {A084A130-28AE-4B32-B51A-1C8CE164BC88} - hxxp://www.convergysworkathome.com/AppHardT.CAB
DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} -

hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} -

hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} -

hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
TCP: DhcpNameServer = [removed] [removed]
TCP: Interfaces\{07CDE4B2-FC88-4355-8166-CDA3EE1C0D13} : DhcpNameServer = [removed] [removed]
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - c:\progra~1\micros~2\office12\GR99D3~1.DLL
Notify: 14390e54741 - c:\windows\system32\catsrvut32.dll
AppInit_DLLs: c:\windows\system32\catsrvut32.dll c:\windows\system32\guard32.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} -

c:\progra~1\micros~2\office12\GRA8E1~1.DLL
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\documents and settings\courtney\application data\mozilla\firefox\profiles\rb8qmi4a.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.yahoo.com/search?ei=UTF-8&fr=ytff-&p=
FF - prefs.js: browser.search.selectedEngine - Yahoo
FF - prefs.js: browser.startup.homepage - hxxp://www.yahoo.com
FF - prefs.js: keyword.URL - hxxp://search.yahoo.com/search?ei=UTF-8&fr=ytff-&p=
FF - component: c:\documents and settings\courtney\application

data\mozilla\firefox\profiles\rb8qmi4a.default\extensions\{88c7f2aa-f93f-432c-8f0e-b7d85967a527}\components\RadioWM

PCoreGecko19.dll
FF - component: c:\documents and settings\courtney\application

data\mozilla\firefox\profiles\rb8qmi4a.default\extensions\[removed]\components\RadioWMPCoreGecko19.dll
FF - plugin: c:\documents and settings\courtney\local settings\application

data\google\update\1.3.21.69\npGoogleUpdate3.dll
FF - plugin: c:\program files\adobe\reader 9.0\reader\air\nppdf32.dll
FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\mozilla

firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} - c:\program files\mozilla

firefox\extensions\{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} - c:\program files\mozilla

firefox\extensions\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} - c:\program files\mozilla

firefox\extensions\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} - c:\program files\mozilla

firefox\extensions\{CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}
FF - Ext: Conduit Engine : [removed] - %profile%\extensions\[removed]
FF - Ext: Personas: [removed] - %profile%\extensions\[removed]
FF - Ext: ColorfulTabs: {0545b830-f0aa-4d7e-8820-50a4629a56fe} -

%profile%\extensions\{0545b830-f0aa-4d7e-8820-50a4629a56fe}
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} -

%profile%\extensions\{20a82645-c095-46ed-80e3-08825760534b}
FF - Ext: Yahoo! Toolbar: {635abd67-4fe9-1b23-4f01-e679fa7484c1} -

%profile%\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
FF - Ext: Personas Rotator: {6e73f6b7-b9ab-44b8-b744-6393e3c2e351} -

%profile%\extensions\{6e73f6b7-b9ab-44b8-b744-6393e3c2e351}
FF - Ext: BitTorrentBar Community Toolbar: {88c7f2aa-f93f-432c-8f0e-b7d85967a527} -

%profile%\extensions\{88c7f2aa-f93f-432c-8f0e-b7d85967a527}
FF - Ext: XUL Cache: {b776c0de-a035-4ce5-9180-fe73cace9434} -

%profile%\extensions\{b776c0de-a035-4ce5-9180-fe73cace9434}
FF - Ext: Pink Fox: {e7348bc0-16f6-11de-8c30-0800200c9a66} -

%profile%\extensions\{e7348bc0-16f6-11de-8c30-0800200c9a66}
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} -

c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\DotNetAssistantExtension
FF - Ext: Java Quick Starter: [removed] - c:\program files\java\jre6\lib\deploy\jqs\ff
.
—- FIREFOX POLICIES —-
FF - user.js: yahoo.homepage.dontask - true
============= SERVICES / DRIVERS ===============
.
R1 cmdGuard;COMODO Internet Security Sandbox Driver;c:\windows\system32\drivers\cmdguard.sys [2010-3-4 134344]
R1 cmdHlp;COMODO Internet Security Helper Driver;c:\windows\system32\drivers\cmdhlp.sys [2010-3-4 25160]
R2 cmdAgent;COMODO Internet Security Helper Service;c:\program files\comodo\comodo internet security\cmdagent.exe

[2010-3-4 723632]
R2 WSWNA1100;WSWNA1100;c:\program files\netgear\wna1100\WifiSvc.exe [2011-4-11 268768]
R3 JSWSCIMD;jswscimd Service;c:\windows\system32\drivers\jswscimd.sys [2011-4-11 57440]
R3 MAUSBPRODUCER;Service for M-Audio Producer;c:\windows\system32\drivers\MAudioProducer.sys [2011-2-24 158344]
S3 AR9271;Atheros AR9271 Wireless Network Adapter Service;c:\windows\system32\drivers\athuw.sys [2011-4-11 1723840]
S3 jswpsapi;JumpStart Wi-Fi Protected Setup;c:\program files\netgear\wna1100\jswpsapi.exe [2011-4-11 360529]
S3 McComponentHostService;McAfee Security Scan Component Host Service;c:\program files\mcafee security

scan\2.0.181\McCHSvc.exe [2010-1-15 227232]
S3 RTLWUSB;NETGEAR WG111v2 54Mbps Wireless USB 2.0 Adapter NT Driver;c:\windows\system32\drivers\wg111v2.sys

–> c:\windows\system32\drivers\wg111v2.sys [?]
S4 Roxio UPnP Renderer 10;Roxio UPnP Renderer 10;c:\program files\roxio\digital home 10\RoxioUPnPRenderer10.exe

[2007-8-24 72176]
S4 Roxio Upnp Server 10;Roxio Upnp Server 10;c:\program files\roxio\digital home 10\RoxioUpnpService10.exe [2007-8-24

362992]
S4 RoxLiveShare10;LiveShare P2P Server 10;c:\program files\common files\roxio

shared\10.0\sharedcom\RoxLiveShare10.exe [2007-8-24 309744]
S4 RoxMediaDB10;RoxMediaDB10;c:\program files\common files\roxio shared\10.0\sharedcom\RoxMediaDB10.exe

[2007-8-24 1083888]
S4 RoxWatch10;Roxio Hard Drive Watcher 10;c:\program files\common files\roxio shared\10.0\sharedcom\RoxWatch10.exe

[2007-8-24 166384]
S4 SessionLauncher;SessionLauncher;c:\docume~1\courtney\locals~1\temp\dx9\sessionlauncher.exe –>

c:\docume~1\courtney\locals~1\temp\dx9\SessionLauncher.exe [?]
.
=============== Created Last 30 ================
.
2011-09-29 22:58:52 388096 —-a-r- c:\documents and settings\courtney\application

data\microsoft\installer\{45a66726-69bc-466b-a7a4-12fcba4883d7}\HiJackThis.exe
2011-09-29 22:58:51 ——– d—–w- c:\program files\Trend Micro
2011-09-28 05:01:56 139656 -c—-w- c:\windows\system32\dllcache\rdpwd.sys
2011-09-28 05:01:49 105472 -c—-w- c:\windows\system32\dllcache\mup.sys
2011-09-28 04:57:10 10496 -c—-w- c:\windows\system32\dllcache\ndistapi.sys
2011-09-09 09:12:13 599040 -c—-w- c:\windows\system32\dllcache\crypt32.dll
.
==================== Find3M ====================
.
2011-09-09 09:12:13 599040 —-a-w- c:\windows\system32\crypt32.dll
2011-08-31 22:00:50 22216 —-a-w- c:\windows\system32\drivers\mbam.sys
2011-08-05 22:21:21 565813 —-a-w- c:\documents and settings\courtney\karplayer.tmp
2011-08-05 20:40:47 53248 —-a-w- c:\documents and settings\courtney\lametritonus_en.dll
2011-08-05 20:40:47 162304 —-a-w- c:\documents and settings\courtney\lame_enc_en.dll
2011-07-15 13:29:31 456320 —-a-w- c:\windows\system32\drivers\mrxsmb.sys
2011-07-08 14:02:00 10496 —-a-w- c:\windows\system32\drivers\ndistapi.sys
2010-01-28 06:06:27 203776 –sh–w- c:\windows\system32\unrar.exe
.
=================== ROOTKIT ====================
.
Stealth MBR rootkit/Mebroot/Sinowal/TDL4 detector 0.4.2 by Gmer, http://www.gmer.net
Windows 5.1.2600 Disk: ST3120213AS rev.3.AHL -> Harddisk0\DR0 -> \Device\Ide\IdePort0 P0T0L0-3
.
device: opened successfully
user: MBR read successfully
.
Disk trace:
called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll >>UNKNOWN [0x85D4A439]<<
_asm { PUSH EBP; MOV EBP, ESP; PUSH ECX; MOV EAX, [EBP+0x8]; CMP EAX, [0x85d507b8]; MOV EAX, [0x85d50834];

PUSH EBX; PUSH ESI; MOV ESI, [EBP+0xc]; MOV EBX, [ESI+0x60]; PUSH EDI; JNZ 0x20; MOV [EBP+0x8], EAX; }
1 ntkrnlpa!IofCallDriver[0x804EE130] -> \Device\Harddisk0\DR0[0x85D1BAB8]
3 CLASSPNP[0xF76BCFD7] -> ntkrnlpa!IofCallDriver[0x804EE130] -> \Device\00000062[0x85D38F18]
5 ACPI[0xF7553620] -> ntkrnlpa!IofCallDriver[0x804EE130] -> [0x85DDA940]
\Driver\atapi[0x85D5AB20] -> IRP_MJ_CREATE -> 0x85D4A439
kernel: MBR read successfully
_asm { XOR AX, AX; MOV SS, AX; MOV SP, 0x7c00; STI ; PUSH AX; POP ES; PUSH AX; POP DS; CLD ; MOV SI, 0x7c1b; MOV

DI, 0x61b; PUSH AX; PUSH DI; MOV CX, 0x1e5; REP MOVSB ; RETF ; MOV BP, 0x7be; MOV CL, 0x4; CMP [BP+0x0], CH; JL

0x2e; JNZ 0x3a; }
detected disk devices:
\Device\Ide\IdeDeviceP0T0L0-3 ->

\??\IDE#DiskST3120213AS_____________________________3.AHL___#5&555aac1&0&0.0.0#{53f56307-b6bf-11d0-94f2-00a0c91

efb8b} device not found
detected hooks:
\Driver\atapi DriverStartIo -> 0x85D4A27F
user & kernel MBR OK
Warning: possible TDL3 rootkit infection !
.
============= FINISH: 20:34:35.71 ===============

.


UNLESS SPECIFICALLY

INSTRUCTED, DO NOT POST

THIS LOG.
IF REQUESTED, ZIP IT UP &

ATTACH IT
.
DDS (Ver_2011-08-26.01)
.
Microsoft Windows XP

Professional
Boot Device:

\Device\HarddiskVolume1
Install Date: 1/6/2010

1:59:44 AM
System Uptime: 10/3/2011

7:30:16 PM (1 hours ago)
.
Motherboard: ECS

|

| Alhena5
Processor: Intel®

Celeron® D CPU 3.33GHz |

CPU 1 | 3324/133mhz
.
==== Disk Partitions

=======================

==
.
C: is FIXED (NTFS) - 106 GiB

total, 58.165 GiB free.
D: is FIXED (NTFS) - 6 GiB

total, 0.876 GiB free.
E: is CDROM ()
.
==== Disabled Device

Manager Items

=============
.
Class GUID:

{4D36E97E-E325-11CE-BFC

1-08002BE10318}
Description: Video Controller

(VGA Compatible)
Device ID:

PCI\VEN_1002&DEV_5A61&

SUBSYS_2A4F103C&REV_0

0\4&1CF2FBB4&0&2808
Manufacturer:
Name: Video Controller (VGA

Compatible)
PNP Device ID:

PCI\VEN_1002&DEV_5A61&

SUBSYS_2A4F103C&REV_0

0\4&1CF2FBB4&0&2808
Service:
.
Class GUID:

{4D36E97E-E325-11CE-BFC

1-08002BE10318}
Description: SM Bus

Controller
Device ID:

PCI\VEN_1002&DEV_4385&

SUBSYS_2A4F103C&REV_1

3\3&267A616A&0&A0
Manufacturer:
Name: SM Bus Controller
PNP Device ID:

PCI\VEN_1002&DEV_4385&

SUBSYS_2A4F103C&REV_1

3\3&267A616A&0&A0
Service:
.
==== System Restore Points

===================
.
No restore point in system.
.
==== Installed Programs

======================
.
Adobe AIR
Adobe Audition 2.0
Adobe Bridge 1.0
Adobe Common File Installer
Adobe Flash Player 10

ActiveX
Adobe Flash Player 10

Plugin
Adobe Help Center 2.0
Adobe Reader 9.4.5
ASIO4ALL
ATI - Software Uninstall

Utility
BitTorrent
BitTorrentBar Toolbar
CCleaner
COMODO Internet Security
COWON Media Center -

jetAudio Basic VX
Data Fax SoftModem with

SmartCP
DirectXInstallService
Driver Detective
EA Download Manager
EMC 10 Content
Express Dictate
Express Scribe
FrostWire 4.21.7
FrostWire 5.0.8
GoGear VIBE Device

Manager
Google Chrome
HiJackThis
Hotfix for Microsoft .NET

Framework 3.5 SP1

(KB953595)
Hotfix for Microsoft .NET

Framework 3.5 SP1

(KB958484)
Hotfix for Windows Media

Format 11 SDK (KB929399)
Hotfix for Windows Media

Player 11 (KB939683)
Hotfix for Windows XP

(KB2158563)
Hotfix for Windows XP

(KB2443685)
Hotfix for Windows XP

(KB2570791)
Hotfix for Windows XP

(KB952287)
Hotfix for Windows XP

(KB954550-v5)
Hotfix for Windows XP

(KB961118)
Hotfix for Windows XP

(KB976098-v2)
Hotfix for Windows XP

(KB979306)
HP Product Detection
HP Update
Java Auto Updater
Java™ 6 Update 26
M-Audio Producer Driver

6.0.4 (x86)
Malwarebytes' Anti-Malware

version 1.51.2.1300
McAfee Security Scan Plus
Media Converter for Philips
Microsoft .NET Framework

1.1
Microsoft .NET Framework

1.1 Security Update

(KB2416447)
Microsoft .NET Framework

2.0 Service Pack 2
Microsoft .NET Framework

3.0 Service Pack 2
Microsoft .NET Framework

3.5 SP1
Microsoft Compression

Client Pack 1.0 for Windows

XP
Microsoft Office Access MUI

(English) 2007
Microsoft Office Access Setup

Metadata MUI (English) 2007
Microsoft Office Enterprise

2007
Microsoft Office Excel MUI

(English) 2007
Microsoft Office Groove MUI

(English) 2007
Microsoft Office Groove

Setup Metadata MUI

(English) 2007
Microsoft Office InfoPath MUI

(English) 2007
Microsoft Office OneNote

MUI (English) 2007
Microsoft Office Outlook MUI

(English) 2007
Microsoft Office PowerPoint

MUI (English) 2007
Microsoft Office Proof

(English) 2007
Microsoft Office Proof

(French) 2007
Microsoft Office Proof

(Spanish) 2007
Microsoft Office Proofing

(English) 2007
Microsoft Office Publisher

MUI (English) 2007
Microsoft Office Shared MUI

(English) 2007
Microsoft Office Shared

Setup Metadata MUI

(English) 2007
Microsoft Office Word MUI

(English) 2007
Microsoft Software Update

for Web Folders (English) 12
Microsoft User-Mode Driver

Framework Feature Pack 1.0
Microsoft Visual C++ 2005

Redistributable
Microsoft Visual C++ 2008

Redistributable - x86

9.0.30729.17
Microsoft WSE 3.0 Runtime
Mozilla Firefox (3.6.17)
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 (KB973688)
MSXML 4.0 SP2 Parser and

SDK
MSXML 6 Service Pack 2

(KB973686)
NETGEAR WNA1100 wireless

USB 2.0 adapter
NETGEAR XET1001

Powerline Encryption Utility
Realtek High Definition

Audio Driver
Roxio Activation Module
Roxio BackOnTrack
Roxio Central Audio
Roxio Central Copy
Roxio Central Core
Roxio Central Data
Roxio Central Tools
Roxio CinePlayer
Roxio CinePlayer Decoder

Pack
Roxio Disc Gallery
Roxio Easy Media Creator 10

Suite
Roxio File Backup
Roxio MediaShare
Security Update for Microsoft

.NET Framework 3.5 SP1

(KB2416473)
Security Update for Windows

Internet Explorer 8

(KB2360131)
Security Update for Windows

Internet Explorer 8

(KB2416400)
Security Update for Windows

Internet Explorer 8

(KB2482017)
Security Update for Windows

Internet Explorer 8

(KB2510531)
Security Update for Windows

Internet Explorer 8

(KB2544521)
Security Update for Windows

Internet Explorer 8

(KB2559049)
Security Update for Windows

Internet Explorer 8

(KB971961)
Security Update for Windows

Internet Explorer 8

(KB976325)
Security Update for Windows

Internet Explorer 8

(KB978207)
Security Update for Windows

Internet Explorer 8

(KB981332)
Security Update for Windows

Media Player (KB2378111)
Security Update for Windows

Media Player (KB952069)
Security Update for Windows

Media Player (KB954155)
Security Update for Windows

Media Player (KB968816)
Security Update for Windows

Media Player (KB973540)
Security Update for Windows

Media Player (KB975558)
Security Update for Windows

Media Player (KB978695)
Security Update for Windows

Media Player 11 (KB954154)
Security Update for Windows

XP (KB2079403)
Security Update for Windows

XP (KB2115168)
Security Update for Windows

XP (KB2121546)
Security Update for Windows

XP (KB2229593)
Security Update for Windows

XP (KB2259922)
Security Update for Windows

XP (KB2279986)
Security Update for Windows

XP (KB2286198)
Security Update for Windows

XP (KB2296011)
Security Update for Windows

XP (KB2296199)
Security Update for Windows

XP (KB2347290)
Security Update for Windows

XP (KB2360937)
Security Update for Windows

XP (KB2387149)
Security Update for Windows

XP (KB2393802)
Security Update for Windows

XP (KB2412687)
Security Update for Windows

XP (KB2419632)
Security Update for Windows

XP (KB2423089)
Security Update for Windows

XP (KB2436673)
Security Update for Windows

XP (KB2440591)
Security Update for Windows

XP (KB2443105)
Security Update for Windows

XP (KB2476490)
Security Update for Windows

XP (KB2476687)
Security Update for Windows

XP (KB2478960)
Security Update for Windows

XP (KB2478971)
Security Update for Windows

XP (KB2479628)
Security Update for Windows

XP (KB2479943)
Security Update for Windows

XP (KB2481109)
Security Update for Windows

XP (KB2483185)
Security Update for Windows

XP (KB2485376)
Security Update for Windows

XP (KB2485663)
Security Update for Windows

XP (KB2503665)
Security Update for Windows

XP (KB2506212)
Security Update for Windows

XP (KB2507618)
Security Update for Windows

XP (KB2507938)
Security Update for Windows

XP (KB2508272)
Security Update for Windows

XP (KB2508429)
Security Update for Windows

XP (KB2509553)
Security Update for Windows

XP (KB2535512)
Security Update for Windows

XP (KB2536276-v2)
Security Update for Windows

XP (KB2544893)
Security Update for Windows

XP (KB2555917)
Security Update for Windows

XP (KB2562937)
Security Update for Windows

XP (KB2566454)
Security Update for Windows

XP (KB2567680)
Security Update for Windows

XP (KB2570222)
Security Update for Windows

XP (KB2570947)
Security Update for Windows

XP (KB923561)
Security Update for Windows

XP (KB923789)
Security Update for Windows

XP (KB941569)
Security Update for Windows

XP (KB946648)
Security Update for Windows

XP (KB950762)
Security Update for Windows

XP (KB950974)
Security Update for Windows

XP (KB951066)
Security Update for Windows

XP (KB951376-v2)
Security Update for Windows

XP (KB951748)
Security Update for Windows

XP (KB952004)
Security Update for Windows

XP (KB952954)
Security Update for Windows

XP (KB955069)
Security Update for Windows

XP (KB956572)
Security Update for Windows

XP (KB956744)
Security Update for Windows

XP (KB956802)
Security Update for Windows

XP (KB956803)
Security Update for Windows

XP (KB956844)
Security Update for Windows

XP (KB957097)
Security Update for Windows

XP (KB958644)
Security Update for Windows

XP (KB958687)
Security Update for Windows

XP (KB958869)
Security Update for Windows

XP (KB959426)
Security Update for Windows

XP (KB960225)
Security Update for Windows

XP (KB960803)
Security Update for Windows

XP (KB960859)
Security Update for Windows

XP (KB961371-v2)
Security Update for Windows

XP (KB961501)
Security Update for Windows

XP (KB969059)
Security Update for Windows

XP (KB969947)
Security Update for Windows

XP (KB970238)
Security Update for Windows

XP (KB970430)
Security Update for Windows

XP (KB971468)
Security Update for Windows

XP (KB971486)
Security Update for Windows

XP (KB971557)
Security Update for Windows

XP (KB971633)
Security Update for Windows

XP (KB971657)
Security Update for Windows

XP (KB972270)
Security Update for Windows

XP (KB973354)
Security Update for Windows

XP (KB973507)
Security Update for Windows

XP (KB973525)
Security Update for Windows

XP (KB973869)
Security Update for Windows

XP (KB973904)
Security Update for Windows

XP (KB974112)
Security Update for Windows

XP (KB974318)
Security Update for Windows

XP (KB974392)
Security Update for Windows

XP (KB974571)
Security Update for Windows

XP (KB975025)
Security Update for Windows

XP (KB975467)
Security Update for Windows

XP (KB975560)
Security Update for Windows

XP (KB975561)
Security Update for Windows

XP (KB975562)
Security Update for Windows

XP (KB975713)
Security Update for Windows

XP (KB976325)
Security Update for Windows

XP (KB977165-v2)
Security Update for Windows

XP (KB977816)
Security Update for Windows

XP (KB977914)
Security Update for Windows

XP (KB978037)
Security Update for Windows

XP (KB978251)
Security Update for Windows

XP (KB978262)
Security Update for Windows

XP (KB978338)
Security Update for Windows

XP (KB978542)
Security Update for Windows

XP (KB978601)
Security Update for Windows

XP (KB978706)
Security Update for Windows

XP (KB979309)
Security Update for Windows

XP (KB979482)
Security Update for Windows

XP (KB979683)
Security Update for Windows

XP (KB979687)
Security Update for Windows

XP (KB980195)
Security Update for Windows

XP (KB980232)
Security Update for Windows

XP (KB980436)
Security Update for Windows

XP (KB981322)
Security Update for Windows

XP (KB981852)
Security Update for Windows

XP (KB981957)
Security Update for Windows

XP (KB981997)
Security Update for Windows

XP (KB982132)
Security Update for Windows

XP (KB982214)
Security Update for Windows

XP (KB982665)
SmartSound Quicktracks

Plugin
SwitchVid 1.11.0901
System Requirements Lab

CYRI
The Sims™ 3
Update for Microsoft .NET

Framework 3.5 SP1

(KB963707)
Update for Windows Internet

Explorer 8 (KB975364)
Update for Windows Internet

Explorer 8 (KB976662)
Update for Windows Internet

Explorer 8 (KB980182)
Update for Windows XP

(KB2141007)
Update for Windows XP

(KB2345886)
Update for Windows XP

(KB2467659)
Update for Windows XP

(KB2541763)
Update for Windows XP

(KB2616676-v2)
Update for Windows XP

(KB951978)
Update for Windows XP

(KB955759)
Update for Windows XP

(KB967715)
Update for Windows XP

(KB968389)
Update for Windows XP

(KB971029)
Update for Windows XP

(KB971737)
Update for Windows XP

(KB973687)
Update for Windows XP

(KB973815)
VLC media player 1.1.8
WebFldrs XP
Windows Genuine Advantage

Notifications (KB905474)
Windows Imaging

Component
Windows Installer Clean Up
Windows Internet Explorer 8
Windows Media Format 11

runtime
Windows Media Player 11
Windows XP Service Pack 3
Yahoo! Install Manager
Yahoo! Messenger
Yahoo! Software Update
Yahoo! Toolbar
.
==== Event Viewer Messages

From Past Week ========
.
9/27/2011 7:50:23 PM,

error: W32Time [17] - Time

Provider NtpClient: An error

occurred during DNS lookup

of the manually configured

peer 'time.windows.com,0x1'.

NtpClient will try the DNS

lookup again in 15 minutes.

The error was: A socket

operation was attempted to

an unreachable host.

(0x80072751)
.
==== End Of File

=======================

====



aswMBR version 0.9.8.986 Copyright© 2011 AVAST Software
Run date: 2011-10-03 21:02:20
—————————–
21:02:20.448 OS Version: Windows 5.1.2600 Service Pack 3
21:02:20.448 Number of processors: 1 586 0x605
21:02:20.448 ComputerName: CCARTER UserName:
21:02:20.713 Initialize success
21:05:26.291 AVAST engine defs: 11100301
21:06:35.104 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdePort0
21:06:35.104 Disk 0 Vendor: ST3120213AS 3.AHL Size: 114473MB BusType: 3
21:06:35.120 Device \Device\Ide\IdeDeviceP0T0L0-3 -> \??\IDE#DiskST3120213AS_____________________________3.AHL___#5&555aac1&0&0.0.0#{53f56307-b6bf-11d0-94f2-00a0c91efb8b} not found
21:06:35.135 Device \Driver\atapi -> DriverStartIo 85d4a27f
21:06:37.151 Disk 0 MBR read successfully
21:06:37.166 Disk 0 MBR scan
21:06:37.229 Disk 0 MBR:Alureon-C [Rtk]
21:06:37.245 Disk 0 TDL4@MBR code has been found
21:06:37.260 Disk 0 Windows XP default MBR code found via API
21:06:37.276 Disk 0 MBR hidden
21:06:37.291 Disk 0 MBR [TDL4] **ROOTKIT**
21:06:37.307 Disk 0 trace - called modules:
21:06:37.323 ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll >>UNKNOWN [0x85d4a439]<<
21:06:39.010 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x85d1bab8]
21:06:39.088 3 CLASSPNP.SYS[f76bcfd7] -> nt!IofCallDriver -> \Device\00000062[0x85d38f18]
21:06:39.182 5 ACPI.sys[f7553620] -> nt!IofCallDriver -> [0x85dda940]
21:06:39.260 \Driver\atapi[0x85d5ab20] -> IRP_MJ_CREATE -> 0x85d4a439
21:06:39.620 AVAST engine scan C:\WINDOWS
21:06:49.948 AVAST engine scan C:\WINDOWS\system32
21:09:12.791 AVAST engine scan C:\WINDOWS\system32\drivers
21:09:49.120 AVAST engine scan C:\Documents and Settings\Courtney
21:22:40.307 AVAST engine scan C:\Documents and Settings\All Users
21:23:19.854 Scan finished successfully
21:52:51.307 Disk 0 MBR has been saved successfully to "C:\Documents and Settings\Courtney\Desktop\MBR.dat"
21:52:51.323 The log file has been saved successfully to "C:\Documents and Settings\Courtney\Desktop\cccaswMBR.txt"
Hello cc78233 :),

Please backup your data.

These articles; System Backup for Windows XP, XP Backup, Windows 7 Backup and Restore, explain the whats and hows using the Windows built-in backup tool.

Some good and free alternative third party backup or imaging softwares that you can consider are Cobian Backup and Macrium Reflect. Tutorial for Cobian Backup can be found here and Macrium Reflect here.

For paid version, Acronis True Image Home is a good option.

To create a boot CD with alternative Operating System, you can try Puppy Linux or xPUD.

Please save a copy of C:\Documents and Settings\Courtney\Desktop\MBR.dat to another location as a backup as well. We might need to fall back on it.

After you have done doing backup, please let me know so that we can continue.

——————–

The earlier DDS logs are not readable due to formatting issue, so I need your help to adjust it. If you have save them, open the logs. On the Menu bar in Notepad, select Format and click on WordWrap so it appears unchecked (unticked). Post the logs.
If you did not save them, please repeat the DDS step, then post the logs with the same setting.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI