This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Delayed Writer Failed...virus, malware? [Solved]

33 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I am utilizing my Dell laptop computer to make this posting as yesterday my HP desktop computer was invadied with some sort of virus that has totally taken over my desktop with multiple messages about "delayed writer failed", plus other opp-ups claiming my RAM and Hard Drive are in seriuos condition. My HP desktop is an older computer that I have upgraded the RAM and replaced the hard drive about 9 months ago …and with the help of a professional computer guy who helped me with the Hard Drive changeover. He explained that I likely did not need to run AVG antivirus as I had done for a number of years, but rather simply run Microsoft Security Essentials and Malwarebytes to protect my computer. This has worked very well till yesterday. My computer is running Windows XP Home Edition, version 2002, Service Pack #3 I usually run Malwarebytes and Security Essentials scans at least once ever week, and I clean out my web searching download files every day. When this virus arrived I was searching the internet and the desktop (on which I have a lot of files and images) went blank and I received multiple messages (windows) claiming "delayed writer failed" with reference to "file\\ System 32 \\ …………..number series" And then I received this message about wanting to scan my computer for problems and likely offerring me to purchase some piece of bulls… software to clean it up (these people should serve a jail term). I resisted this notion to use that carp** but I could not get their window off my computer, nor access anything else. I subsequently open my computer in Safe Mode and somehow (don't remember exactly) looked at the history of my Security Essentials antivirus and saw that I had contacted about 3 viruses yesterday, and about 3 several days ago. BUT it was indicated that SE recognized these threads and isolated them (neutralized them?). I tried to run Malwarebytes in the Safe Mode but could not. In fact I can not run anything more on that computer that I know how? I need some help, please. You guys were great last Jan when I had problems with the Dell laptop I using right now to contact you.
Hello beiland and welcome to the WTT forum.

My name is Satchfan and I would be glad to help you with your computer problem.

Please read the following guidelines which will help to make cleaning your machine easier:
  • please follow all instructions in the order posted
  • please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear
  • all logs/reports, etc. must be posted in Notepad. Please ensure that word wrap is unchecked. In Notepad click Format, uncheck Word wrap if it is checked
  • if you don't understand something, please don't hesitate to ask for clarification before proceeding
  • the fixes are specific to your problem and should only be used for this issue on this machine.
  • please reply within 3 days. If you do not reply within this period I will post a reminder but topics with no reply in 4 days will be closed!
IMPORTANT:

Please DO NOT install/uninstall any programs unless asked to.
Please DO NOT run any scans other than those requested

I will reply with instructions shortly

Satchfan
Hello again beiland

Download/run Rkill:

Please download Rkill from one of the following links and save to your Desktop:

Link One
Link Two
Link Three
Link Four

  • Double click on Rkill.
  • A command window will open then disappear upon completion, this is normal.
  • Please leave Rkill on the Desktop until otherwise advised.
Note: If you get an alert that Rkill is infected, ignore it. The alert is a fake warning given by the rogue software which attempts to terminate tools that try to remove it. If you see such a warning, leave the warning on the screen and then run Rkill again. By not closing the warning, this sometimes allows you to bypass the malware's attempt to protect itself so that Rkill can perform its routine.

You may have to make repeated attempts to use Rkill several times before it will run as some malware variants try to block it.

You'll be able to tell when rkill has done its job when your desktop (explorer.exe) cycles off and then on again.

===================================================

Run OTL

download OTL and save it to your desktop.
  • double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted
  • when the window appears, underneath Output at the top change it to Minimal Output
  • check the boxes beside LOP Check and Purity Check
  • click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan won’t take long
  • when the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt.
Note: These logs can be located in the OTL. folder on you C:\ drive if they fail to open automatically.

Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post them with your next reply. You may need two posts to fit them both in.

===================================================

Run aswMBR
  • download aswMBR.exe to your desktop.
  • double click the aswMBR.exe to run it
  • if asked, accept the AVAST virus definition download
  • click the "Scan" button to start scan
  • on completion of the scan click Save log, save it to your desktop and post in your next reply
Logs to include with next post:

OTL.txt
Extras.txt
aswMBR log


Thanks

Satchfan

Hello beiland and welcome to the WTT forum.

My name is Satchfan and I would be glad to help you with your computer problem.

IMPORTANT:

Please DO NOT install/uninstall any programs unless asked to.
Please DO NOT run any scans other than those requested

I will reply with instructions shortly

Satchfan

Hello Satchfan,
My working hours are kind of strange so I just got back to your message late this evening,…but need to go to bed right away for an early morning job. i will be back with you late tomorrow afternoon or evening.

I found it rather strange that you should offer this advice about 'not running any other scans or programs',…then right below that statement was an advertisement for a free piece of scanning software :)
Cheers, & thanks in advance for your help

Hello again beiland

Download/run Rkill:

Please download Rkill from one of the following links and save to your Desktop:

Quick question, can I download something to that desktop computer of mine operating in the safe mode? To my knowledge I can't access anything in the regular mode as my desktop is totally void except for their window with the their message to me to run their scan of my computer….plus the multiple windows announcing 'delayed write failed'
Hi beiland

My working hours are kind of strange

No problem – you’ll probably have to near with me also as I’m in the UK.

===============================================

I found it rather strange that you should offer this advice about 'not running any other scans or programs',…then right below that statement was an advertisement for a free piece of scanning software

What advertisement? There is none that I am aware of and none that I can see under that section you mentioned. :scratch:

===============================================

Boot to Safe mode with Networking and see if you can then download the files. If you can’t access the Internet that way either, try to download and save the files to a flash drive and then transfer them to the desktop of the infected computer

Satchfan
My first two scans posted here…I'll have to do that third one later today
OTL.Txt
OTL Extras logfile created on: 12/3/2011 12:08:59 PM - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Documents and Settings\Brian\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

991.48 Mb Total Physical Memory | 740.95 Mb Available Physical Memory | 74.73% Memory free
2.34 Gb Paging File | 2.16 Gb Available in Paging File | 92.39% Paging File free
Paging file location(s): C:\pagefile.sys 1488 2976 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 149.04 Gb Total Space | 131.87 Gb Free Space | 88.48% Space Free | Partition Type: NTFS
Drive F: | 1.88 Gb Total Space | 1.87 Gb Free Space | 99.93% Space Free | Partition Type: FAT

Computer Name: BRIANS | User Name: Brian | Logged in as Administrator.
Boot Mode: SafeMode with Networking | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] – "%1" %*
htmlfile – Reg Error: Key error.
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\Skype\Plugin Manager\skypePM.exe" = C:\Program Files\Skype\Plugin Manager\skypePM.exe:*:Enabled:Skype Extras Manager
"C:\Program Files\Common Files\Apple\Apple Application Support\WebKit2WebProcess.exe" = C:\Program Files\Common Files\Apple\Apple Application Support\WebKit2WebProcess.exe:*:Enabled:WebKit – (Apple Inc.)


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{05BFB060-4F22-4710-B0A2-2801A1B606C5}" = Microsoft Antimalware
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{26A24AE4-039D-4CA4-87B4-2F83216020FF}" = Java™ 6 Update 26
"{26A24AE4-039D-4CA4-87B4-2F83216022F0}" = Java™ 6 Update 22
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{3E171899-0175-47CC-84C4-562ACDD4C021}" = OpenOffice.org 3.3
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{54B6DC7D-8C5B-4DFB-BC15-C010A3326B2B}" = Microsoft Security Client
"{6A3F9D74-BB80-4451-8CA1-4B3A857F1359}" = Apple Application Support
"{76EFFC7C-17A6-479D-9E47-8E658C1695AE}" = Windows Backup Utility
"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
"{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{AA59DDE4-B672-4621-A016-4C248204957A}" = Skype™ 5.5
"{AC76BA86-7AD7-1033-7B44-A94000000001}" = Adobe Reader 9.4.6
"{B194272D-1F92-46DF-99EB-8D5CE91CB4EC}" = Adobe AIR
"{B6CF2967-C81E-40C0-9815-C05774FEF120}" = Skype Click to Call
"{C9E14402-3631-4182-B377-6B0DFB1C0339}" = QuickTime
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"ie8" = Windows Internet Explorer 8
"ieSpell" = ieSpell
"IrfanView" = IrfanView (remove only)
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware version 1.51.2.1300
"Microsoft Security Client" = Microsoft Security Essentials
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"NVIDIA Drivers" = NVIDIA Drivers
"OneTouch Version 3.0" = OneTouch Version 3.0
"PaperPort 7.02" = PaperPort 7.02
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 3
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 8/14/2011 8:03:42 PM | Computer Name = BRIAN-LDRXJVN9X | Source = Application Hang | ID = 1002
Description = Hanging application iexplore.exe, version 8.0.6001.18702, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 8/16/2011 6:04:50 PM | Computer Name = BRIAN-LDRXJVN9X | Source = Application Hang | ID = 1002
Description = Hanging application iexplore.exe, version 8.0.6001.18702, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 8/31/2011 4:31:48 PM | Computer Name = BRIAN-LDRXJVN9X | Source = MPSampleSubmission | ID = 5000
Description = EventType mptelemetry, P1 8024402c, P2 endsearch, P3 search, P4 3.0.8402.0,
P5 mpsigdwn.dll, P6 3.0.8402.0, P7 microsoft security essentials (edb4fa23-53b8-4afa-8c5d-99752cca7094),
P8 NIL, P9 NIL, P10 NIL.

Error - 8/31/2011 4:37:00 PM | Computer Name = BRIAN-LDRXJVN9X | Source = MPSampleSubmission | ID = 5000
Description = EventType mptelemetry, P1 8024402c, P2 endsearch, P3 search, P4 3.0.8402.0,
P5 mpsigdwn.dll, P6 3.0.8402.0, P7 microsoft security essentials (edb4fa23-53b8-4afa-8c5d-99752cca7094),
P8 NIL, P9 NIL, P10 NIL.

Error - 9/3/2011 3:12:50 PM | Computer Name = BRIAN-LDRXJVN9X | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 8.0.6001.18702, faulting
module unknown, version 0.0.0.0, fault address 0x0d3cf04f.

Error - 9/6/2011 11:34:16 AM | Computer Name = BRIAN-LDRXJVN9X | Source = Application Hang | ID = 1002
Description = Hanging application iexplore.exe, version 8.0.6001.18702, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 9/6/2011 11:51:52 AM | Computer Name = BRIAN-LDRXJVN9X | Source = Application Hang | ID = 1002
Description = Hanging application iexplore.exe, version 8.0.6001.18702, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 9/12/2011 2:25:21 PM | Computer Name = BRIAN-LDRXJVN9X | Source = Application Hang | ID = 1002
Description = Hanging application iexplore.exe, version 8.0.6001.18702, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 9/19/2011 2:51:59 PM | Computer Name = BRIAN-LDRXJVN9X | Source = Application Error | ID = 1000
Description = Faulting application MsMpEng.exe, version 3.0.8402.0, faulting module
mpengine.dll, version 1.1.7604.0, fault address 0x00106172.

Error - 9/19/2011 7:49:18 PM | Computer Name = BRIAN-LDRXJVN9X | Source = Microsoft Security Client | ID = 5000
Description =

[ System Events ]
Error - 12/1/2011 1:37:50 AM | Computer Name = BRIAN-LDRXJVN9X | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service EventSystem
with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}

Error - 12/3/2011 12:24:15 PM | Computer Name = BRIANS | Source = Windows Update Agent | ID = 16
Description = Unable to Connect: Windows is unable to connect to the automatic updates
service and therefore cannot download and install updates according to the set
schedule. Windows will continue to try to establish a connection.

Error - 12/3/2011 12:32:08 PM | Computer Name = BRIANS | Source = Microsoft Antimalware | ID = 1014
Description = %%860 has encountered an error trying to remove history of malware
and other potentially unwanted software. Time: 11/3/2011 11:32:07 AM User: NT AUTHORITY\SYSTEM

Error
Code: 0x80070005 Error description: Access is denied.

Error - 12/3/2011 12:43:05 PM | Computer Name = BRIANS | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service EventSystem
with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}

Error - 12/3/2011 12:44:09 PM | Computer Name = BRIANS | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
AmdK7 Fips MpFilter

Error - 12/3/2011 12:52:33 PM | Computer Name = BRIANS | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service wuauserv with
arguments "" in order to run the server: {E60687F7-01A1-40AA-86AC-DB1CBF673334}

Error - 12/3/2011 12:52:33 PM | Computer Name = BRIANS | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service wuauserv with
arguments "" in order to run the server: {E60687F7-01A1-40AA-86AC-DB1CBF673334}

Error - 12/3/2011 12:52:33 PM | Computer Name = BRIANS | Source = Microsoft Antimalware | ID = 2001
Description = %%860 has encountered an error trying to update signatures. New Signature
Version: Previous Signature Version: 1.115.2858.0 Update Source: %%859 Update Stage:
%%852 Source Path: Default URL Signature Type: %%800 Update Type: %%803 User: NT AUTHORITY\SYSTEM

Current
Engine Version: Previous Engine Version: 1.1.7801.0 Error code: 0x8007043c Error
description: This service cannot be started in Safe Mode

Error - 12/3/2011 12:52:58 PM | Computer Name = BRIANS | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service StiSvc with
arguments "" in order to run the server: {A1F4E726-8CF1-11D1-BF92-0060081ED811}

Error - 12/3/2011 12:53:10 PM | Computer Name = BRIANS | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service StiSvc with
arguments "" in order to run the server: {A1F4E726-8CF1-11D1-BF92-0060081ED811}


< End of report >
***************************************************
OTL logfile created on: 12/3/2011 11:14:18 PM - Run 3
OTL by OldTimer - Version 3.2.31.0 Folder = F:\
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

991.48 Mb Total Physical Memory | 740.49 Mb Available Physical Memory | 74.69% Memory free
2.34 Gb Paging File | 2.14 Gb Available in Paging File | 91.37% Paging File free
Paging file location(s): C:\pagefile.sys 1488 2976 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 149.04 Gb Total Space | 132.43 Gb Free Space | 88.86% Space Free | Partition Type: NTFS
Drive F: | 1.88 Gb Total Space | 1.87 Gb Free Space | 99.90% Space Free | Partition Type: FAT

Computer Name: BRIANS | User Name: Brian | Logged in as Administrator.
Boot Mode: SafeMode | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - F:\OTL.exe (OldTimer Tools)
PRC - C:\Documents and Settings\Brian\Desktop\OTL.exe (OldTimer Tools)
PRC - c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe (Microsoft Corporation)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)


========== Modules (No Company Name) ==========


========== Win32 Services (SafeList) ==========

SRV - (HidServ) – File not found
SRV - (AppMgmt) – File not found
SRV - (MsMpSvc) – c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe (Microsoft Corporation)


========== Driver Services (SafeList) ==========

DRV - (KMWDFILTER) – C:\WINDOWS\system32\drivers\KMWDFILTER.sys (Windows ® Codename Longhorn DDK provider)
DRV - (gameenum) – C:\WINDOWS\system32\drivers\gameenum.sys (Microsoft Corporation)
DRV - (nvnforce) Service for NVIDIA® nForce™ – C:\WINDOWS\system32\drivers\nvapu.sys (NVIDIA Corporation)
DRV - (nvax) Service for NVIDIA® nForce™ – C:\WINDOWS\system32\drivers\nvax.sys (NVIDIA Corporation)
DRV - (ltmodem5) – C:\WINDOWS\system32\drivers\ltmdmnt.sys (Agere Systems)
DRV - (NVENET) – C:\WINDOWS\system32\drivers\NVENET.sys (NVIDIA Corporation)
DRV - (ms_mpu401) – C:\WINDOWS\system32\drivers\msmpu401.sys (Microsoft Corporation)
DRV - (ppsio2) – C:\WINDOWS\System32\drivers\ppsio2.sys ()


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========


IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)



O1 HOSTS File: ([2003/07/16 15:29:34 | 000,000,734 | -H– | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O4 - HKLM..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k File not found
O4 - HKLM..\Run: [LTMSG] C:\WINDOWS\ltmsg.exe (Agere Systems)
O4 - HKLM..\Run: [MSC] c:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
O4 - HKLM..\Run: [OneTouch Monitor] C:\Program Files\Visioneer OneTouch\OneTouchMon.exe (Visioneer Inc)
O4 - HKLM..\Run: [vMttfGqwJXmmgo.exe] C:\Documents and Settings\All Users\Application Data\vMttfGqwJXmmgo.exe ()
O4 - HKCU..\Run: [PPWebCap] C:\Program Files\ScanSoft\PaperPort\PPWEBCAP.EXE (Scansoft Inc.)
O4 - Startup: C:\Documents and Settings\Brian\Start Menu\Programs\Startup\OpenOffice.org 3.3.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableTaskMgr = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: &ieSpell Options - C:\Program Files\ieSpell\iespell.dll (Red Egg Software)
O8 - Extra context menu item: Check &Spelling - C:\Program Files\ieSpell\iespell.dll (Red Egg Software)
O8 - Extra context menu item: Lookup on Merriam Webster - C:\Program Files\ieSpell\Merriam Webster.HTM ()
O8 - Extra context menu item: Lookup on Wikipedia - C:\Program Files\ieSpell\wikipedia.HTM ()
O9 - Extra Button: ieSpell - {0E17D5B7-9F5D-4fee-9DF6-CA6EE38B68A8} - C:\Program Files\ieSpell\iespell.dll (Red Egg Software)
O9 - Extra 'Tools' menuitem : ieSpell - {0E17D5B7-9F5D-4fee-9DF6-CA6EE38B68A8} - C:\Program Files\ieSpell\iespell.dll (Red Egg Software)
O9 - Extra 'Tools' menuitem : ieSpell Options - {1606D6F9-9D3B-4aea-A025-ED5B2FD488E7} - C:\Program Files\ieSpell\iespell.dll (Red Egg Software)
O9 - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O16 - DPF: {38AB0814-B09B-4378-9940-14A19638C3C2} http://www.auctiva.com/Aurigma/ImageUploader57.cab (Auctiva Image Uploader Control)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://update.microsoft.com/windowsupdate/…b?1281530804562 (WUWebControl Class)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://www.update.microsoft.com/microsoftu…b?1281533633281 (MUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://download.macromedia.com/pub/shockwa…ash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{74154A94-5F2B-46A0-A274-CDAA7769E700}: DhcpNameServer = 192.168.0.1
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20 - AppInit_DLLs: (NVDESK32.DLL) - File not found
O20 - HKLM Winlogon: Shell - (Explorer.exe) -C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) -C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2010/08/11 07:36:55 | 000,000,000 | -H– | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2011/12/03 12:05:08 | 000,584,192 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Brian\Desktop\OTL.exe
[2011/12/03 11:22:48 | 000,000,000 | RH-D | C] – C:\Documents and Settings\Brian\Recent
[2011/11/30 12:51:07 | 000,000,000 | -H-D | C] – C:\Documents and Settings\Brian\Start Menu\Programs\System Fix
[2011/11/15 15:55:56 | 000,000,000 | -H-D | C] – C:\Documents and Settings\Brian\My Documents\DudleyDix 55 stuff
[5 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2011/12/03 22:59:16 | 000,584,192 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Brian\Desktop\OTL.exe
[2011/12/03 22:31:55 | 000,000,424 | -H– | M] () – C:\WINDOWS\tasks\MP Scheduled Scan.job
[2011/12/03 22:25:01 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2011/12/03 12:00:49 | 001,008,114 | —- | M] () – C:\Documents and Settings\Brian\Desktop\rkill.exe
[2011/12/03 11:29:00 | 000,000,422 | -H– | M] () – C:\WINDOWS\tasks\User_Feed_Synchronization-{2DD1C23A-87F8-45BF-96AB-C10466627E93}.job
[2011/12/03 11:21:55 | 000,013,646 | -H– | M] () – C:\WINDOWS\System32\wpa.dbl
[2011/11/30 12:55:06 | 000,000,849 | -H– | M] () – C:\Documents and Settings\Brian\Application Data\Microsoft\Internet Explorer\Quick Launch\System Fix.lnk
[2011/11/30 12:51:32 | 000,000,416 | -H– | M] () – C:\Documents and Settings\All Users\Application Data\IBGAOVNqVpnBcv
[2011/11/30 12:51:09 | 000,000,831 | -H– | M] () – C:\Documents and Settings\Brian\Desktop\System Fix.lnk
[2011/11/30 12:51:09 | 000,000,312 | -H– | M] () – C:\Documents and Settings\All Users\Application Data\~IBGAOVNqVpnBcv
[2011/11/30 12:51:09 | 000,000,216 | -H– | M] () – C:\Documents and Settings\All Users\Application Data\~IBGAOVNqVpnBcvr
[2011/11/30 12:50:56 | 000,352,256 | -H– | M] () – C:\Documents and Settings\All Users\Application Data\IBGAOVNqVpnBcv.exe
[2011/11/30 12:44:04 | 000,445,312 | -H– | M] () – C:\Documents and Settings\All Users\Application Data\vMttfGqwJXmmgo.exe
[2011/11/29 13:14:46 | 000,000,077 | -H– | M] () – C:\WINDOWS\mydebug.ini
[2011/11/25 11:11:06 | 000,263,214 | -H– | M] () – C:\Documents and Settings\Brian\Desktop\Hydrogen Peroxide Cancer Treatment - Alternative Cancer Treatments.mht
[2011/11/24 13:03:02 | 000,000,284 | -H– | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2011/11/24 00:27:43 | 000,414,368 | -H– | M] (Adobe Systems Incorporated) – C:\WINDOWS\System32\FlashPlayerCPLApp.cpl
[2011/11/23 14:58:51 | 000,054,017 | -H– | M] () – C:\Documents and Settings\Brian\Desktop\A47-aft-deck-7.jpg
[2011/11/09 22:51:57 | 000,001,374 | -H– | M] () – C:\WINDOWS\imsins.BAK
[2011/11/09 17:34:04 | 000,292,513 | -H– | M] () – C:\Documents and Settings\Brian\My Documents\NorCore plastic honeycomb.pdf
[2011/11/06 09:47:05 | 000,311,604 | -H– | M] () – C:\WINDOWS\System32\perfh009.dat
[2011/11/06 09:47:05 | 000,039,992 | -H– | M] () – C:\WINDOWS\System32\perfc009.dat
[5 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files Created - No Company Name ==========

[2011/12/03 12:00:47 | 001,008,114 | —- | C] () – C:\Documents and Settings\Brian\Desktop\rkill.exe
[2011/11/30 12:55:05 | 000,000,849 | -H– | C] () – C:\Documents and Settings\Brian\Application Data\Microsoft\Internet Explorer\Quick Launch\System Fix.lnk
[2011/11/30 12:51:09 | 000,000,831 | -H– | C] () – C:\Documents and Settings\Brian\Desktop\System Fix.lnk
[2011/11/30 12:51:09 | 000,000,312 | -H– | C] () – C:\Documents and Settings\All Users\Application Data\~IBGAOVNqVpnBcv
[2011/11/30 12:51:09 | 000,000,216 | -H– | C] () – C:\Documents and Settings\All Users\Application Data\~IBGAOVNqVpnBcvr
[2011/11/30 12:51:03 | 000,000,416 | -H– | C] () – C:\Documents and Settings\All Users\Application Data\IBGAOVNqVpnBcv
[2011/11/30 12:50:55 | 000,352,256 | -H– | C] () – C:\Documents and Settings\All Users\Application Data\IBGAOVNqVpnBcv.exe
[2011/11/30 12:47:08 | 000,445,312 | -H– | C] () – C:\Documents and Settings\All Users\Application Data\vMttfGqwJXmmgo.exe
[2011/11/25 11:11:06 | 000,263,214 | -H– | C] () – C:\Documents and Settings\Brian\Desktop\Hydrogen Peroxide Cancer Treatment - Alternative Cancer Treatments.mht
[2011/11/23 17:06:48 | 000,054,017 | -H– | C] () – C:\Documents and Settings\Brian\Desktop\A47-aft-deck-7.jpg
[2011/11/09 17:34:04 | 000,292,513 | -H– | C] () – C:\Documents and Settings\Brian\My Documents\NorCore plastic honeycomb.pdf
[2011/07/13 18:13:34 | 000,000,077 | -H– | C] () – C:\WINDOWS\mydebug.ini
[2010/12/14 09:58:02 | 000,023,200 | -H– | C] () – C:\WINDOWS\System32\drivers\ppsio2.sys
[2010/12/14 09:52:34 | 000,000,090 | -H– | C] () – C:\WINDOWS\calera.ini
[2010/09/13 16:26:58 | 000,000,056 | -H– | C] () – C:\WINDOWS\System32\ezsidmv.dat
[2010/09/11 16:47:33 | 000,006,656 | -H– | C] () – C:\Documents and Settings\Brian\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/08/25 19:33:07 | 000,001,456 | -H– | C] () – C:\WINDOWS\MAXLINK.INI
[2010/08/25 19:33:00 | 000,269,312 | -H– | C] () – C:\WINDOWS\System32\FPXIG.DLL
[2010/08/25 19:33:00 | 000,068,096 | -H– | C] () – C:\WINDOWS\System32\IGFPX32P.DLL
[2010/08/25 19:33:00 | 000,065,024 | -H– | C] () – C:\WINDOWS\System32\JPEGACC.DLL
[2010/08/25 19:32:40 | 000,101,376 | -H– | C] () – C:\WINDOWS\System32\WELSOF32.DLL
[2010/08/17 20:58:39 | 000,000,664 | -H– | C] () – C:\WINDOWS\System32\d3d9caps.dat
[2010/08/11 08:09:31 | 000,004,569 | -H– | C] () – C:\WINDOWS\System32\secupd.dat
[2010/08/11 07:41:07 | 000,002,048 | –S- | C] () – C:\WINDOWS\bootstat.dat
[2010/08/11 07:34:53 | 000,021,640 | -H– | C] () – C:\WINDOWS\System32\emptyregdb.dat
[2010/08/11 03:31:43 | 000,004,161 | -H– | C] () – C:\WINDOWS\ODBCINST.INI
[2010/08/11 03:30:24 | 000,119,744 | -H– | C] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2003/07/16 15:54:55 | 000,004,594 | -H– | C] () – C:\WINDOWS\System32\oembios.dat
[2003/07/16 15:54:54 | 013,107,200 | -H– | C] () – C:\WINDOWS\System32\oembios.bin
[2003/07/16 15:41:25 | 000,311,604 | -H– | C] () – C:\WINDOWS\System32\perfh009.dat
[2003/07/16 15:41:25 | 000,272,128 | -H– | C] () – C:\WINDOWS\System32\perfi009.dat
[2003/07/16 15:41:23 | 000,028,626 | -H– | C] () – C:\WINDOWS\System32\perfd009.dat
[2003/07/16 15:41:21 | 000,039,992 | -H– | C] () – C:\WINDOWS\System32\perfc009.dat
[2003/07/16 15:39:07 | 000,000,741 | -H– | C] () – C:\WINDOWS\System32\noise.dat
[2003/07/16 15:33:50 | 000,673,088 | -H– | C] () – C:\WINDOWS\System32\mlang.dat
[2003/07/16 15:33:39 | 000,046,258 | -H– | C] () – C:\WINDOWS\System32\mib.bin
[2003/07/16 15:27:41 | 000,218,003 | -H– | C] () – C:\WINDOWS\System32\dssec.dat
[2003/07/16 15:26:37 | 000,001,804 | -H– | C] () – C:\WINDOWS\System32\dcache.bin
[2002/03/31 13:03:00 | 000,001,024 | -H– | C] () – C:\WINDOWS\System32\drivers\jedih2rx.bin
[2002/03/31 13:03:00 | 000,000,122 | -H– | C] () – C:\WINDOWS\System32\drivers\ramsed.bin

========== LOP Check ==========

[2010/09/01 10:48:52 | 000,000,000 | -H-D | M] – C:\Documents and Settings\Brian\Application Data\ieSpell
[2010/08/11 08:16:46 | 000,000,000 | -H-D | M] – C:\Documents and Settings\Brian\Application Data\OpenOffice.org
[2011/12/03 22:31:55 | 000,000,424 | -H– | M] () – C:\WINDOWS\Tasks\MP Scheduled Scan.job
[2011/12/03 11:29:00 | 000,000,422 | -H– | M] () – C:\WINDOWS\Tasks\User_Feed_Synchronization-{2DD1C23A-87F8-45BF-96AB-C10466627E93}.job

========== Purity Check ==========



< End of report >
aswMBR version 0.9.8.986 Copyright© 2011 AVAST Software Run date: 2011-12-03 23:23:41 —————————– 23:23:41.562 OS Version: Windows 5.1.2600 Service Pack 3 23:23:41.562 Number of processors: 1 586 0x602 23:23:41.562 ComputerName: BRIANS UserName: Brian 23:23:44.609 Initialize success 23:24:29.156 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-3 23:24:29.171 Disk 0 Vendor: WDC_WD1600AAJB-00J3A0 01.03E01 Size: 152627MB BusType: 3 23:24:29.203 Disk 0 MBR read successfully 23:24:29.218 Disk 0 MBR scan 23:24:29.234 Disk 0 Windows XP default MBR code 23:24:29.265 Disk 0 scanning sectors +312560640 23:24:29.406 Disk 0 scanning C:\WINDOWS\system32\drivers 23:24:47.625 Service scanning 23:24:55.093 Modules scanning 23:25:02.062 Disk 0 trace - called modules: 23:25:02.109 ntoskrnl.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll atapi.sys pciide.sys 23:25:02.125 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x85cb1ab8] 23:25:02.156 3 CLASSPNP.SYS[f74c7fd7] -> nt!IofCallDriver -> \Device\00000061[0x85cd1910] 23:25:02.171 5 ACPI.sys[f743e620] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP0T0L0-3[0x85cd5940] 23:25:06.796 Scan finished successfully 23:25:31.718 Disk 0 MBR has been saved successfully to "C:\Documents and Settings\Brian\Desktop\MBR.dat" 23:25:31.750 The log file has been saved successfully to "C:\Documents and Settings\Brian\Desktop\aswMBR.txt"
OKAY, I think these 3 scans above are the ones you wanted?? While I was on that infected desktop computer I managed to access the 'history' of my antivirus software "Microsoft Security Essentials". Here are the viruses it listed as captured by them……. and filtered out?? Trojan: Win 32 / Alureon.FL Trojan: Win 32 / Alureon.AE Exploit: Java / Blacole.AW Exploit: Java / Blacole AV Exploit: Java / Blacole AS Exploit: Java / Blacole AV Exploit: Java / Blacole AT I've taken tomorrow off from work so i can work on this if you have time. I'm in Wash DC, so about 6 hrs behind you. Regards, Brian
Hello again beiland

Please do not run any scans unless I advise you or you may not be able to recover some of your programs/files.

Run RogueKiller

Note: Do not reboot your computer if at all possible otherwise the malware will reactivate and you will have to run RogueKiller again

Download RogueKiller to your desktop.
  • close all running programs
  • for Windows Vista/Seven, right click -> run as administrator, for XP simply double-click on RogueKiller.exe
  • when prompted, type 1 and press Enter
  • the RKreport.txt will be generated next to the executable, (on the desktop).
    If the program is blocked, do not hesitate to try several times. If it really does not work (it could happen), rename it to winlogon.exe
Please post the contents of the RKreport.txt in your next Reply.

Remember: do not reboot your computer if at all possible otherwise the malware will reactivate and you will have to run RogueKiller again

Satchfan
RogueKiller V6.1.12 [12/02/2011] by Tigzy
mail: tigzyRKgmailcom
Feedback: http://www.geekstogo.com/forum/files/file/413-roguekiller/
Blog: http://tigzyrk.blogspot.com

Operating System: Windows XP (5.1.2600 Service Pack 3) 32 bits version
Started in : Safe mode
User: Brian [Admin rights]
Mode: Scan – Date : 12/04/2011 08:48:46

¤¤¤ Bad processes: 0 ¤¤¤

¤¤¤ Registry Entries: 5 ¤¤¤
[SUSP PATH] HKLM\[…]\Run : vMttfGqwJXmmgo.exe (C:\Documents and Settings\All Users\Application Data\vMttfGqwJXmmgo.exe) -> FOUND
[HJPOL] HKLM\[…]\System : DisableTaskMgr (1) -> FOUND
[HJ] HKCU\[…]\Advanced : Start_ShowMyComputer (0) -> FOUND
[HJ] HKCU\[…]\Advanced : Start_ShowSearch (0) -> FOUND
[HJ] HKLM\[…]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> FOUND

¤¤¤ Particular Files / Folders: ¤¤¤

¤¤¤ Driver: [NOT LOADED] ¤¤¤

¤¤¤ Infection : ¤¤¤

¤¤¤ HOSTS File: ¤¤¤
127.0.0.1 localhost


Finished : << RKreport[1].txt >>
RKreport[1].txt
Run RogueKiller

Close all running programs and run RogueKiller once again.
  • for Vista/Seven, right click -> run as administrator, for XP simply run RogueKiller.exe
  • when prompted, type 2 and then press Enter
  • the RKreport.txt will be generated next to RogueKiller.exe (on the desktop, if that is where you saved the program
  • if the program is blocked, do not hesitate to try several times. If it really does not work (it could happen), rename it to winlogon.exe
Please post the contents of the RKreport.txt in your next reply.

===================================================

Run TDSSKiller

Please download TDSSKiller.zip
  • Extract it to your desktop
  • Double click TDSSKiller.exe
  • Press Start Scan
    • Only if Malicious objects are found then ensure Cure is selected
    • Then click Continue > Reboot now
  • Copy and paste the log in your next reply
    • A copy of the log will be saved automatically to the root of the drive (typically C:\) called TDSSKiller_*** (*** denotes version & date)

Please also remember to include RKreport.txt and let me know if there are any changes

Thanks

Satchfan
my second run of this

RogueKiller V6.1.12 [12/02/2011] by Tigzy
mail: tigzyRKgmailcom
Feedback: http://www.geekstogo.com/forum/files/file/413-roguekiller/
Blog: http://tigzyrk.blogspot.com

Operating System: Windows XP (5.1.2600 Service Pack 3) 32 bits version
Started in : Safe mode
User: Brian [Admin rights]
Mode: Scan – Date : 12/04/2011 10:03:52

¤¤¤ Bad processes: 0 ¤¤¤

¤¤¤ Registry Entries: 5 ¤¤¤
[SUSP PATH] HKLM\[…]\Run : vMttfGqwJXmmgo.exe (C:\Documents and Settings\All Users\Application Data\vMttfGqwJXmmgo.exe) -> FOUND
[HJPOL] HKLM\[…]\System : DisableTaskMgr (1) -> FOUND
[HJ] HKCU\[…]\Advanced : Start_ShowMyComputer (0) -> FOUND
[HJ] HKCU\[…]\Advanced : Start_ShowSearch (0) -> FOUND
[HJ] HKLM\[…]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> FOUND

¤¤¤ Particular Files / Folders: ¤¤¤

¤¤¤ Driver: [NOT LOADED] ¤¤¤

¤¤¤ Infection : ¤¤¤

¤¤¤ HOSTS File: ¤¤¤
127.0.0.1 localhost


Finished : << RKreport[2].txt >>
RKreport[1].txt ; RKreport[2].txt

***********************************************************************
Upon running TDSSKiller I got the responce that there were NO corrupted or neutralized objects…so no report

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI