Delayed Writer Failed...virus, malware? [Solved]
33 min read
My name is Satchfan and I would be glad to help you with your computer problem.
Please read the following guidelines which will help to make cleaning your machine easier:
- please follow all instructions in the order posted
- please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear
- all logs/reports, etc. must be posted in Notepad. Please ensure that word wrap is unchecked. In Notepad click Format, uncheck Word wrap if it is checked
- if you don't understand something, please don't hesitate to ask for clarification before proceeding
- the fixes are specific to your problem and should only be used for this issue on this machine.
- please reply within 3 days. If you do not reply within this period I will post a reminder but topics with no reply in 4 days will be closed!
Please DO NOT install/uninstall any programs unless asked to.
Please DO NOT run any scans other than those requested
I will reply with instructions shortly
Satchfan
Download/run Rkill:
Please download Rkill from one of the following links and save to your Desktop:
Link One
Link Two
Link Three
Link Four
- Double click on Rkill.
- A command window will open then disappear upon completion, this is normal.
- Please leave Rkill on the Desktop until otherwise advised.
You may have to make repeated attempts to use Rkill several times before it will run as some malware variants try to block it.
You'll be able to tell when rkill has done its job when your desktop (explorer.exe) cycles off and then on again.
===================================================
Run OTL
download OTL and save it to your desktop.
- double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted
- when the window appears, underneath Output at the top change it to Minimal Output
- check the boxes beside LOP Check and Purity Check
- click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan won’t take long
- when the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt.
Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post them with your next reply. You may need two posts to fit them both in.
===================================================
Run aswMBR
- download aswMBR.exe to your desktop.
- double click the aswMBR.exe to run it
- if asked, accept the AVAST virus definition download
- click the "Scan" button to start scan
- on completion of the scan click Save log, save it to your desktop and post in your next reply
OTL.txt
Extras.txt
aswMBR log
Thanks
Satchfan
Hello Satchfan,Hello beiland and welcome to the WTT forum.
My name is Satchfan and I would be glad to help you with your computer problem.
IMPORTANT:
Please DO NOT install/uninstall any programs unless asked to.
Please DO NOT run any scans other than those requested
I will reply with instructions shortly
Satchfan
My working hours are kind of strange so I just got back to your message late this evening,…but need to go to bed right away for an early morning job. i will be back with you late tomorrow afternoon or evening.
I found it rather strange that you should offer this advice about 'not running any other scans or programs',…then right below that statement was an advertisement for a free piece of scanning software
Cheers, & thanks in advance for your help
Quick question, can I download something to that desktop computer of mine operating in the safe mode? To my knowledge I can't access anything in the regular mode as my desktop is totally void except for their window with the their message to me to run their scan of my computer….plus the multiple windows announcing 'delayed write failed'Hello again beiland
Download/run Rkill:
Please download Rkill from one of the following links and save to your Desktop:
No problem – you’ll probably have to near with me also as I’m in the UK.My working hours are kind of strange
===============================================
What advertisement? There is none that I am aware of and none that I can see under that section you mentioned.I found it rather strange that you should offer this advice about 'not running any other scans or programs',…then right below that statement was an advertisement for a free piece of scanning software
===============================================
Boot to Safe mode with Networking and see if you can then download the files. If you can’t access the Internet that way either, try to download and save the files to a flash drive and then transfer them to the desktop of the infected computer
Satchfan
OTL.Txt
OTL Extras logfile created on: 12/3/2011 12:08:59 PM - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Documents and Settings\Brian\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
991.48 Mb Total Physical Memory | 740.95 Mb Available Physical Memory | 74.73% Memory free
2.34 Gb Paging File | 2.16 Gb Available in Paging File | 92.39% Paging File free
Paging file location(s): C:\pagefile.sys 1488 2976 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 149.04 Gb Total Space | 131.87 Gb Free Space | 88.48% Space Free | Partition Type: NTFS
Drive F: | 1.88 Gb Total Space | 1.87 Gb Free Space | 99.93% Space Free | Partition Type: FAT
Computer Name: BRIANS | User Name: Brian | Logged in as Administrator.
Boot Mode: SafeMode with Networking | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Extra Registry (SafeList) ==========
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
========== Shell Spawning ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] – "%1" %*
htmlfile – Reg Error: Key error.
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]
========== System Restore Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2
========== Firewall Settings ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002
========== Authorized Applications List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\Skype\Plugin Manager\skypePM.exe" = C:\Program Files\Skype\Plugin Manager\skypePM.exe:*:Enabled:Skype Extras Manager
"C:\Program Files\Common Files\Apple\Apple Application Support\WebKit2WebProcess.exe" = C:\Program Files\Common Files\Apple\Apple Application Support\WebKit2WebProcess.exe:*:Enabled:WebKit – (Apple Inc.)
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{05BFB060-4F22-4710-B0A2-2801A1B606C5}" = Microsoft Antimalware
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{26A24AE4-039D-4CA4-87B4-2F83216020FF}" = Java™ 6 Update 26
"{26A24AE4-039D-4CA4-87B4-2F83216022F0}" = Java™ 6 Update 22
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{3E171899-0175-47CC-84C4-562ACDD4C021}" = OpenOffice.org 3.3
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{54B6DC7D-8C5B-4DFB-BC15-C010A3326B2B}" = Microsoft Security Client
"{6A3F9D74-BB80-4451-8CA1-4B3A857F1359}" = Apple Application Support
"{76EFFC7C-17A6-479D-9E47-8E658C1695AE}" = Windows Backup Utility
"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
"{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{AA59DDE4-B672-4621-A016-4C248204957A}" = Skype™ 5.5
"{AC76BA86-7AD7-1033-7B44-A94000000001}" = Adobe Reader 9.4.6
"{B194272D-1F92-46DF-99EB-8D5CE91CB4EC}" = Adobe AIR
"{B6CF2967-C81E-40C0-9815-C05774FEF120}" = Skype Click to Call
"{C9E14402-3631-4182-B377-6B0DFB1C0339}" = QuickTime
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"ie8" = Windows Internet Explorer 8
"ieSpell" = ieSpell
"IrfanView" = IrfanView (remove only)
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware version 1.51.2.1300
"Microsoft Security Client" = Microsoft Security Essentials
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"NVIDIA Drivers" = NVIDIA Drivers
"OneTouch Version 3.0" = OneTouch Version 3.0
"PaperPort 7.02" = PaperPort 7.02
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 3
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
========== Last 10 Event Log Errors ==========
[ Application Events ]
Error - 8/14/2011 8:03:42 PM | Computer Name = BRIAN-LDRXJVN9X | Source = Application Hang | ID = 1002
Description = Hanging application iexplore.exe, version 8.0.6001.18702, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.
Error - 8/16/2011 6:04:50 PM | Computer Name = BRIAN-LDRXJVN9X | Source = Application Hang | ID = 1002
Description = Hanging application iexplore.exe, version 8.0.6001.18702, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.
Error - 8/31/2011 4:31:48 PM | Computer Name = BRIAN-LDRXJVN9X | Source = MPSampleSubmission | ID = 5000
Description = EventType mptelemetry, P1 8024402c, P2 endsearch, P3 search, P4 3.0.8402.0,
P5 mpsigdwn.dll, P6 3.0.8402.0, P7 microsoft security essentials (edb4fa23-53b8-4afa-8c5d-99752cca7094),
P8 NIL, P9 NIL, P10 NIL.
Error - 8/31/2011 4:37:00 PM | Computer Name = BRIAN-LDRXJVN9X | Source = MPSampleSubmission | ID = 5000
Description = EventType mptelemetry, P1 8024402c, P2 endsearch, P3 search, P4 3.0.8402.0,
P5 mpsigdwn.dll, P6 3.0.8402.0, P7 microsoft security essentials (edb4fa23-53b8-4afa-8c5d-99752cca7094),
P8 NIL, P9 NIL, P10 NIL.
Error - 9/3/2011 3:12:50 PM | Computer Name = BRIAN-LDRXJVN9X | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 8.0.6001.18702, faulting
module unknown, version 0.0.0.0, fault address 0x0d3cf04f.
Error - 9/6/2011 11:34:16 AM | Computer Name = BRIAN-LDRXJVN9X | Source = Application Hang | ID = 1002
Description = Hanging application iexplore.exe, version 8.0.6001.18702, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.
Error - 9/6/2011 11:51:52 AM | Computer Name = BRIAN-LDRXJVN9X | Source = Application Hang | ID = 1002
Description = Hanging application iexplore.exe, version 8.0.6001.18702, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.
Error - 9/12/2011 2:25:21 PM | Computer Name = BRIAN-LDRXJVN9X | Source = Application Hang | ID = 1002
Description = Hanging application iexplore.exe, version 8.0.6001.18702, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.
Error - 9/19/2011 2:51:59 PM | Computer Name = BRIAN-LDRXJVN9X | Source = Application Error | ID = 1000
Description = Faulting application MsMpEng.exe, version 3.0.8402.0, faulting module
mpengine.dll, version 1.1.7604.0, fault address 0x00106172.
Error - 9/19/2011 7:49:18 PM | Computer Name = BRIAN-LDRXJVN9X | Source = Microsoft Security Client | ID = 5000
Description =
[ System Events ]
Error - 12/1/2011 1:37:50 AM | Computer Name = BRIAN-LDRXJVN9X | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service EventSystem
with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}
Error - 12/3/2011 12:24:15 PM | Computer Name = BRIANS | Source = Windows Update Agent | ID = 16
Description = Unable to Connect: Windows is unable to connect to the automatic updates
service and therefore cannot download and install updates according to the set
schedule. Windows will continue to try to establish a connection.
Error - 12/3/2011 12:32:08 PM | Computer Name = BRIANS | Source = Microsoft Antimalware | ID = 1014
Description = %%860 has encountered an error trying to remove history of malware
and other potentially unwanted software. Time: 11/3/2011 11:32:07 AM User: NT AUTHORITY\SYSTEM
Error
Code: 0x80070005 Error description: Access is denied.
Error - 12/3/2011 12:43:05 PM | Computer Name = BRIANS | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service EventSystem
with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}
Error - 12/3/2011 12:44:09 PM | Computer Name = BRIANS | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
AmdK7 Fips MpFilter
Error - 12/3/2011 12:52:33 PM | Computer Name = BRIANS | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service wuauserv with
arguments "" in order to run the server: {E60687F7-01A1-40AA-86AC-DB1CBF673334}
Error - 12/3/2011 12:52:33 PM | Computer Name = BRIANS | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service wuauserv with
arguments "" in order to run the server: {E60687F7-01A1-40AA-86AC-DB1CBF673334}
Error - 12/3/2011 12:52:33 PM | Computer Name = BRIANS | Source = Microsoft Antimalware | ID = 2001
Description = %%860 has encountered an error trying to update signatures. New Signature
Version: Previous Signature Version: 1.115.2858.0 Update Source: %%859 Update Stage:
%%852 Source Path: Default URL Signature Type: %%800 Update Type: %%803 User: NT AUTHORITY\SYSTEM
Current
Engine Version: Previous Engine Version: 1.1.7801.0 Error code: 0x8007043c Error
description: This service cannot be started in Safe Mode
Error - 12/3/2011 12:52:58 PM | Computer Name = BRIANS | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service StiSvc with
arguments "" in order to run the server: {A1F4E726-8CF1-11D1-BF92-0060081ED811}
Error - 12/3/2011 12:53:10 PM | Computer Name = BRIANS | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service StiSvc with
arguments "" in order to run the server: {A1F4E726-8CF1-11D1-BF92-0060081ED811}
< End of report >
***************************************************
OTL by OldTimer - Version 3.2.31.0 Folder = F:\
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
991.48 Mb Total Physical Memory | 740.49 Mb Available Physical Memory | 74.69% Memory free
2.34 Gb Paging File | 2.14 Gb Available in Paging File | 91.37% Paging File free
Paging file location(s): C:\pagefile.sys 1488 2976 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 149.04 Gb Total Space | 132.43 Gb Free Space | 88.86% Space Free | Partition Type: NTFS
Drive F: | 1.88 Gb Total Space | 1.87 Gb Free Space | 99.90% Space Free | Partition Type: FAT
Computer Name: BRIANS | User Name: Brian | Logged in as Administrator.
Boot Mode: SafeMode | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - F:\OTL.exe (OldTimer Tools)
PRC - C:\Documents and Settings\Brian\Desktop\OTL.exe (OldTimer Tools)
PRC - c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe (Microsoft Corporation)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
========== Modules (No Company Name) ==========
========== Win32 Services (SafeList) ==========
SRV - (HidServ) – File not found
SRV - (AppMgmt) – File not found
SRV - (MsMpSvc) – c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe (Microsoft Corporation)
========== Driver Services (SafeList) ==========
DRV - (KMWDFILTER) – C:\WINDOWS\system32\drivers\KMWDFILTER.sys (Windows ® Codename Longhorn DDK provider)
DRV - (gameenum) – C:\WINDOWS\system32\drivers\gameenum.sys (Microsoft Corporation)
DRV - (nvnforce) Service for NVIDIA® nForce™ – C:\WINDOWS\system32\drivers\nvapu.sys (NVIDIA Corporation)
DRV - (nvax) Service for NVIDIA® nForce™ – C:\WINDOWS\system32\drivers\nvax.sys (NVIDIA Corporation)
DRV - (ltmodem5) – C:\WINDOWS\system32\drivers\ltmdmnt.sys (Agere Systems)
DRV - (NVENET) – C:\WINDOWS\system32\drivers\NVENET.sys (NVIDIA Corporation)
DRV - (ms_mpu401) – C:\WINDOWS\system32\drivers\msmpu401.sys (Microsoft Corporation)
DRV - (ppsio2) – C:\WINDOWS\System32\drivers\ppsio2.sys ()
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
O1 HOSTS File: ([2003/07/16 15:29:34 | 000,000,734 | -H– | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O4 - HKLM..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k File not found
O4 - HKLM..\Run: [LTMSG] C:\WINDOWS\ltmsg.exe (Agere Systems)
O4 - HKLM..\Run: [MSC] c:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
O4 - HKLM..\Run: [OneTouch Monitor] C:\Program Files\Visioneer OneTouch\OneTouchMon.exe (Visioneer Inc)
O4 - HKLM..\Run: [vMttfGqwJXmmgo.exe] C:\Documents and Settings\All Users\Application Data\vMttfGqwJXmmgo.exe ()
O4 - HKCU..\Run: [PPWebCap] C:\Program Files\ScanSoft\PaperPort\PPWEBCAP.EXE (Scansoft Inc.)
O4 - Startup: C:\Documents and Settings\Brian\Start Menu\Programs\Startup\OpenOffice.org 3.3.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableTaskMgr = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: &ieSpell Options - C:\Program Files\ieSpell\iespell.dll (Red Egg Software)
O8 - Extra context menu item: Check &Spelling - C:\Program Files\ieSpell\iespell.dll (Red Egg Software)
O8 - Extra context menu item: Lookup on Merriam Webster - C:\Program Files\ieSpell\Merriam Webster.HTM ()
O8 - Extra context menu item: Lookup on Wikipedia - C:\Program Files\ieSpell\wikipedia.HTM ()
O9 - Extra Button: ieSpell - {0E17D5B7-9F5D-4fee-9DF6-CA6EE38B68A8} - C:\Program Files\ieSpell\iespell.dll (Red Egg Software)
O9 - Extra 'Tools' menuitem : ieSpell - {0E17D5B7-9F5D-4fee-9DF6-CA6EE38B68A8} - C:\Program Files\ieSpell\iespell.dll (Red Egg Software)
O9 - Extra 'Tools' menuitem : ieSpell Options - {1606D6F9-9D3B-4aea-A025-ED5B2FD488E7} - C:\Program Files\ieSpell\iespell.dll (Red Egg Software)
O9 - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O16 - DPF: {38AB0814-B09B-4378-9940-14A19638C3C2} http://www.auctiva.com/Aurigma/ImageUploader57.cab (Auctiva Image Uploader Control)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://update.microsoft.com/windowsupdate/…b?1281530804562 (WUWebControl Class)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://www.update.microsoft.com/microsoftu…b?1281533633281 (MUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://download.macromedia.com/pub/shockwa…ash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{74154A94-5F2B-46A0-A274-CDAA7769E700}: DhcpNameServer = 192.168.0.1
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20 - AppInit_DLLs: (NVDESK32.DLL) - File not found
O20 - HKLM Winlogon: Shell - (Explorer.exe) -C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) -C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2010/08/11 07:36:55 | 000,000,000 | -H– | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
========== Files/Folders - Created Within 30 Days ==========
[2011/12/03 12:05:08 | 000,584,192 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Brian\Desktop\OTL.exe
[2011/12/03 11:22:48 | 000,000,000 | RH-D | C] – C:\Documents and Settings\Brian\Recent
[2011/11/30 12:51:07 | 000,000,000 | -H-D | C] – C:\Documents and Settings\Brian\Start Menu\Programs\System Fix
[2011/11/15 15:55:56 | 000,000,000 | -H-D | C] – C:\Documents and Settings\Brian\My Documents\DudleyDix 55 stuff
[5 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2011/12/03 22:59:16 | 000,584,192 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Brian\Desktop\OTL.exe
[2011/12/03 22:31:55 | 000,000,424 | -H– | M] () – C:\WINDOWS\tasks\MP Scheduled Scan.job
[2011/12/03 22:25:01 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2011/12/03 12:00:49 | 001,008,114 | —- | M] () – C:\Documents and Settings\Brian\Desktop\rkill.exe
[2011/12/03 11:29:00 | 000,000,422 | -H– | M] () – C:\WINDOWS\tasks\User_Feed_Synchronization-{2DD1C23A-87F8-45BF-96AB-C10466627E93}.job
[2011/12/03 11:21:55 | 000,013,646 | -H– | M] () – C:\WINDOWS\System32\wpa.dbl
[2011/11/30 12:55:06 | 000,000,849 | -H– | M] () – C:\Documents and Settings\Brian\Application Data\Microsoft\Internet Explorer\Quick Launch\System Fix.lnk
[2011/11/30 12:51:32 | 000,000,416 | -H– | M] () – C:\Documents and Settings\All Users\Application Data\IBGAOVNqVpnBcv
[2011/11/30 12:51:09 | 000,000,831 | -H– | M] () – C:\Documents and Settings\Brian\Desktop\System Fix.lnk
[2011/11/30 12:51:09 | 000,000,312 | -H– | M] () – C:\Documents and Settings\All Users\Application Data\~IBGAOVNqVpnBcv
[2011/11/30 12:51:09 | 000,000,216 | -H– | M] () – C:\Documents and Settings\All Users\Application Data\~IBGAOVNqVpnBcvr
[2011/11/30 12:50:56 | 000,352,256 | -H– | M] () – C:\Documents and Settings\All Users\Application Data\IBGAOVNqVpnBcv.exe
[2011/11/30 12:44:04 | 000,445,312 | -H– | M] () – C:\Documents and Settings\All Users\Application Data\vMttfGqwJXmmgo.exe
[2011/11/29 13:14:46 | 000,000,077 | -H– | M] () – C:\WINDOWS\mydebug.ini
[2011/11/25 11:11:06 | 000,263,214 | -H– | M] () – C:\Documents and Settings\Brian\Desktop\Hydrogen Peroxide Cancer Treatment - Alternative Cancer Treatments.mht
[2011/11/24 13:03:02 | 000,000,284 | -H– | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2011/11/24 00:27:43 | 000,414,368 | -H– | M] (Adobe Systems Incorporated) – C:\WINDOWS\System32\FlashPlayerCPLApp.cpl
[2011/11/23 14:58:51 | 000,054,017 | -H– | M] () – C:\Documents and Settings\Brian\Desktop\A47-aft-deck-7.jpg
[2011/11/09 22:51:57 | 000,001,374 | -H– | M] () – C:\WINDOWS\imsins.BAK
[2011/11/09 17:34:04 | 000,292,513 | -H– | M] () – C:\Documents and Settings\Brian\My Documents\NorCore plastic honeycomb.pdf
[2011/11/06 09:47:05 | 000,311,604 | -H– | M] () – C:\WINDOWS\System32\perfh009.dat
[2011/11/06 09:47:05 | 000,039,992 | -H– | M] () – C:\WINDOWS\System32\perfc009.dat
[5 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files Created - No Company Name ==========
[2011/12/03 12:00:47 | 001,008,114 | —- | C] () – C:\Documents and Settings\Brian\Desktop\rkill.exe
[2011/11/30 12:55:05 | 000,000,849 | -H– | C] () – C:\Documents and Settings\Brian\Application Data\Microsoft\Internet Explorer\Quick Launch\System Fix.lnk
[2011/11/30 12:51:09 | 000,000,831 | -H– | C] () – C:\Documents and Settings\Brian\Desktop\System Fix.lnk
[2011/11/30 12:51:09 | 000,000,312 | -H– | C] () – C:\Documents and Settings\All Users\Application Data\~IBGAOVNqVpnBcv
[2011/11/30 12:51:09 | 000,000,216 | -H– | C] () – C:\Documents and Settings\All Users\Application Data\~IBGAOVNqVpnBcvr
[2011/11/30 12:51:03 | 000,000,416 | -H– | C] () – C:\Documents and Settings\All Users\Application Data\IBGAOVNqVpnBcv
[2011/11/30 12:50:55 | 000,352,256 | -H– | C] () – C:\Documents and Settings\All Users\Application Data\IBGAOVNqVpnBcv.exe
[2011/11/30 12:47:08 | 000,445,312 | -H– | C] () – C:\Documents and Settings\All Users\Application Data\vMttfGqwJXmmgo.exe
[2011/11/25 11:11:06 | 000,263,214 | -H– | C] () – C:\Documents and Settings\Brian\Desktop\Hydrogen Peroxide Cancer Treatment - Alternative Cancer Treatments.mht
[2011/11/23 17:06:48 | 000,054,017 | -H– | C] () – C:\Documents and Settings\Brian\Desktop\A47-aft-deck-7.jpg
[2011/11/09 17:34:04 | 000,292,513 | -H– | C] () – C:\Documents and Settings\Brian\My Documents\NorCore plastic honeycomb.pdf
[2011/07/13 18:13:34 | 000,000,077 | -H– | C] () – C:\WINDOWS\mydebug.ini
[2010/12/14 09:58:02 | 000,023,200 | -H– | C] () – C:\WINDOWS\System32\drivers\ppsio2.sys
[2010/12/14 09:52:34 | 000,000,090 | -H– | C] () – C:\WINDOWS\calera.ini
[2010/09/13 16:26:58 | 000,000,056 | -H– | C] () – C:\WINDOWS\System32\ezsidmv.dat
[2010/09/11 16:47:33 | 000,006,656 | -H– | C] () – C:\Documents and Settings\Brian\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/08/25 19:33:07 | 000,001,456 | -H– | C] () – C:\WINDOWS\MAXLINK.INI
[2010/08/25 19:33:00 | 000,269,312 | -H– | C] () – C:\WINDOWS\System32\FPXIG.DLL
[2010/08/25 19:33:00 | 000,068,096 | -H– | C] () – C:\WINDOWS\System32\IGFPX32P.DLL
[2010/08/25 19:33:00 | 000,065,024 | -H– | C] () – C:\WINDOWS\System32\JPEGACC.DLL
[2010/08/25 19:32:40 | 000,101,376 | -H– | C] () – C:\WINDOWS\System32\WELSOF32.DLL
[2010/08/17 20:58:39 | 000,000,664 | -H– | C] () – C:\WINDOWS\System32\d3d9caps.dat
[2010/08/11 08:09:31 | 000,004,569 | -H– | C] () – C:\WINDOWS\System32\secupd.dat
[2010/08/11 07:41:07 | 000,002,048 | –S- | C] () – C:\WINDOWS\bootstat.dat
[2010/08/11 07:34:53 | 000,021,640 | -H– | C] () – C:\WINDOWS\System32\emptyregdb.dat
[2010/08/11 03:31:43 | 000,004,161 | -H– | C] () – C:\WINDOWS\ODBCINST.INI
[2010/08/11 03:30:24 | 000,119,744 | -H– | C] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2003/07/16 15:54:55 | 000,004,594 | -H– | C] () – C:\WINDOWS\System32\oembios.dat
[2003/07/16 15:54:54 | 013,107,200 | -H– | C] () – C:\WINDOWS\System32\oembios.bin
[2003/07/16 15:41:25 | 000,311,604 | -H– | C] () – C:\WINDOWS\System32\perfh009.dat
[2003/07/16 15:41:25 | 000,272,128 | -H– | C] () – C:\WINDOWS\System32\perfi009.dat
[2003/07/16 15:41:23 | 000,028,626 | -H– | C] () – C:\WINDOWS\System32\perfd009.dat
[2003/07/16 15:41:21 | 000,039,992 | -H– | C] () – C:\WINDOWS\System32\perfc009.dat
[2003/07/16 15:39:07 | 000,000,741 | -H– | C] () – C:\WINDOWS\System32\noise.dat
[2003/07/16 15:33:50 | 000,673,088 | -H– | C] () – C:\WINDOWS\System32\mlang.dat
[2003/07/16 15:33:39 | 000,046,258 | -H– | C] () – C:\WINDOWS\System32\mib.bin
[2003/07/16 15:27:41 | 000,218,003 | -H– | C] () – C:\WINDOWS\System32\dssec.dat
[2003/07/16 15:26:37 | 000,001,804 | -H– | C] () – C:\WINDOWS\System32\dcache.bin
[2002/03/31 13:03:00 | 000,001,024 | -H– | C] () – C:\WINDOWS\System32\drivers\jedih2rx.bin
[2002/03/31 13:03:00 | 000,000,122 | -H– | C] () – C:\WINDOWS\System32\drivers\ramsed.bin
========== LOP Check ==========
[2010/09/01 10:48:52 | 000,000,000 | -H-D | M] – C:\Documents and Settings\Brian\Application Data\ieSpell
[2010/08/11 08:16:46 | 000,000,000 | -H-D | M] – C:\Documents and Settings\Brian\Application Data\OpenOffice.org
[2011/12/03 22:31:55 | 000,000,424 | -H– | M] () – C:\WINDOWS\Tasks\MP Scheduled Scan.job
[2011/12/03 11:29:00 | 000,000,422 | -H– | M] () – C:\WINDOWS\Tasks\User_Feed_Synchronization-{2DD1C23A-87F8-45BF-96AB-C10466627E93}.job
========== Purity Check ==========
< End of report >
Please do not run any scans unless I advise you or you may not be able to recover some of your programs/files.
Run RogueKiller
Note: Do not reboot your computer if at all possible otherwise the malware will reactivate and you will have to run RogueKiller again
Download RogueKiller to your desktop.
- close all running programs
- for Windows Vista/Seven, right click -> run as administrator, for XP simply double-click on RogueKiller.exe
- when prompted, type 1 and press Enter
- the RKreport.txt will be generated next to the executable, (on the desktop).
If the program is blocked, do not hesitate to try several times. If it really does not work (it could happen), rename it to winlogon.exe
Remember: do not reboot your computer if at all possible otherwise the malware will reactivate and you will have to run RogueKiller again
Satchfan
mail: tigzyRKgmailcom
Feedback: http://www.geekstogo.com/forum/files/file/413-roguekiller/
Blog: http://tigzyrk.blogspot.com
Operating System: Windows XP (5.1.2600 Service Pack 3) 32 bits version
Started in : Safe mode
User: Brian [Admin rights]
Mode: Scan – Date : 12/04/2011 08:48:46
¤¤¤ Bad processes: 0 ¤¤¤
¤¤¤ Registry Entries: 5 ¤¤¤
[SUSP PATH] HKLM\[…]\Run : vMttfGqwJXmmgo.exe (C:\Documents and Settings\All Users\Application Data\vMttfGqwJXmmgo.exe) -> FOUND
[HJPOL] HKLM\[…]\System : DisableTaskMgr (1) -> FOUND
[HJ] HKCU\[…]\Advanced : Start_ShowMyComputer (0) -> FOUND
[HJ] HKCU\[…]\Advanced : Start_ShowSearch (0) -> FOUND
[HJ] HKLM\[…]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> FOUND
¤¤¤ Particular Files / Folders: ¤¤¤
¤¤¤ Driver: [NOT LOADED] ¤¤¤
¤¤¤ Infection : ¤¤¤
¤¤¤ HOSTS File: ¤¤¤
127.0.0.1 localhost
Finished : << RKreport[1].txt >>
RKreport[1].txt
Close all running programs and run RogueKiller once again.
- for Vista/Seven, right click -> run as administrator, for XP simply run RogueKiller.exe
- when prompted, type 2 and then press Enter
- the RKreport.txt will be generated next to RogueKiller.exe (on the desktop, if that is where you saved the program
- if the program is blocked, do not hesitate to try several times. If it really does not work (it could happen), rename it to winlogon.exe
===================================================
Run TDSSKiller
Please download TDSSKiller.zip
- Extract it to your desktop
- Double click TDSSKiller.exe
- Press Start Scan
- Only if Malicious objects are found then ensure Cure is selected
- Then click Continue > Reboot now
- Copy and paste the log in your next reply
- A copy of the log will be saved automatically to the root of the drive (typically C:\) called TDSSKiller_*** (*** denotes version & date)
Please also remember to include RKreport.txt and let me know if there are any changes
Thanks
Satchfan
RogueKiller V6.1.12 [12/02/2011] by Tigzy
mail: tigzyRKgmailcom
Feedback: http://www.geekstogo.com/forum/files/file/413-roguekiller/
Blog: http://tigzyrk.blogspot.com
Operating System: Windows XP (5.1.2600 Service Pack 3) 32 bits version
Started in : Safe mode
User: Brian [Admin rights]
Mode: Scan – Date : 12/04/2011 10:03:52
¤¤¤ Bad processes: 0 ¤¤¤
¤¤¤ Registry Entries: 5 ¤¤¤
[SUSP PATH] HKLM\[…]\Run : vMttfGqwJXmmgo.exe (C:\Documents and Settings\All Users\Application Data\vMttfGqwJXmmgo.exe) -> FOUND
[HJPOL] HKLM\[…]\System : DisableTaskMgr (1) -> FOUND
[HJ] HKCU\[…]\Advanced : Start_ShowMyComputer (0) -> FOUND
[HJ] HKCU\[…]\Advanced : Start_ShowSearch (0) -> FOUND
[HJ] HKLM\[…]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> FOUND
¤¤¤ Particular Files / Folders: ¤¤¤
¤¤¤ Driver: [NOT LOADED] ¤¤¤
¤¤¤ Infection : ¤¤¤
¤¤¤ HOSTS File: ¤¤¤
127.0.0.1 localhost
Finished : << RKreport[2].txt >>
RKreport[1].txt ; RKreport[2].txt
***********************************************************************
Upon running TDSSKiller I got the responce that there were NO corrupted or neutralized objects…so no report
Ask AI
AI can make mistakes. Check the cited posts. Archived advice can be out-of-date
Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI