Hello JonTom!
First off, thanks for the response. I was able to run DDS and MGADiag, but I'm having problems with GMER Rootkit Scanner. The computer freezes every time I try to perform a scan. I'm sure I followed the instructions carefully…
DDS Logs
.
DDS (Ver_2011-08-26.01) - NTFSx86
Internet Explorer: 6.0.2900.2180
Run by [removed] at 10:22:57 on 2012-08-18
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.382.74 [GMT 8:00]
.
.
============== Running Processes ===============
.
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\Program Files\AVAST Software\Avast\AvastSvc.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\AVAST Software\Avast\avastUI.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\SMART BRO\UIExec.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files\SMART BRO\AssistantServices.exe
C:\Documents and Settings\Administrator\Application Data\mjusbsp\magicJack.exe
C:\Program Files\SMART BRO\UIMain.exe
C:\Program Files\SMART BRO\CMUpdater.exe
C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\WINDOWS\system32\notepad.exe
.
============== Pseudo HJT Report ===============
.
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
uRun: [cdloader] "c:\documents and settings\administrator\application data\mjusbsp\cdloader2.exe" MAGICJACK
mRun: [avast] "c:\program files\avast software\avast\avastUI.exe" /nogui
mRun: [SoundMan] SOUNDMAN.EXE
mRun: [MSConfig] c:\windows\pchealth\helpctr\binaries\MSConfig.exe /auto
mRun: [UIExec] "c:\program files\smart bro\UIExec.exe"
dRun: [TaskSwitchXP] c:\program files\taskswitchxp\TaskSwitchXP.exe
dRun: [Free Download Manager] c:\program files\free download manager\fdm.exe -autorun
dRunOnce: [nlsf] cmd.exe /C move /Y "%SystemRoot%\System32\syssetub.dll" "%SystemRoot%\System32\syssetup.dll"
dRunOnce: [nlhr] RunDll32.exe %SystemRoot%\System32\AdvPack.Dll,LaunchINFSection %SystemRoot%\inf\nlite.inf,C
dRunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe
uPolicies-explorer: NoInstrumentation = 1 (0x1)
mPolicies-explorer: NoDesktopCleanupWizard = 1 (0x1)
dPolicies-explorer: NoInstrumentation = 1 (0x1)
dPolicies-explorer: NoSMHelp = 1 (0x1)
IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0015-0000-0005-ABCDEFFEDCBC} - c:\program files\java\jre1.5.0_05\bin\npjpi150_05.dll
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_05-windows-i586.cab
DPF: {CAFEEFAC-0015-0000-0005-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_05-windows-i586.cab
TCP: Interfaces\{23ABFA1B-9402-40AA-9143-6B0008F0C3A0} : NameServer = 121.1.3.172 121.1.3.89
TCP: Interfaces\{CEB5B662-DCDC-4E20-9C7C-553AE4F099B2} : DhcpNameServer = 192.168.1.1
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\documents and settings\administrator\application data\mozilla\firefox\profiles\ncr9qsox.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: network.proxy.type - 0
FF - component: c:\program files\mozilla firefox\extensions\[removed]\components\qfaservices.dll
FF - plugin: c:\program files\adobe\reader 10.0\reader\air\nppdf32.dll
FF - plugin: c:\program files\google\update\1.3.21.115\npGoogleUpdate3.dll
FF - plugin: c:\windows\system32\adobe\director\np32dsw_1166636.dll
FF - plugin: c:\windows\system32\macromed\flash\NPSWF32_11_3_300_271.dll
.
============= SERVICES / DRIVERS ===============
.
.
=============== File Associations ===============
.
inffile=c:\windows\system32\NOTEPAD2.EXE %1
inifile=c:\windows\system32\NOTEPAD2.EXE %1
txtfile=c:\windows\system32\NOTEPAD2.EXE %1
.
=============== Created Last 30 ================
.
2012-08-17 05:53:45 9216 —-a-w- c:\windows\system32\drivers\massfilter.sys
2012-08-17 05:53:45 107776 —-a-w- c:\windows\system32\drivers\ZTEusbvoice.sys
2012-08-17 05:53:45 107776 —-a-w- c:\windows\system32\drivers\ZTEusbser6k.sys
2012-08-17 05:53:45 107776 —-a-w- c:\windows\system32\drivers\ZTEusbnmea.sys
2012-08-17 05:53:45 107776 —-a-w- c:\windows\system32\drivers\ZTEusbmdm6k.sys
2012-08-17 05:53:13 ——– d—–w- c:\program files\SMART BRO
2012-08-17 05:39:11 ——– d—–w- c:\windows\system32\appmgmt
2012-08-17 05:25:44 ——– d—–w- c:\windows\pss
2012-08-17 03:58:58 ——– d—–w- c:\documents and settings\administrator\application data\Malwarebytes
2012-08-17 03:58:37 ——– d—–w- c:\documents and settings\all users\application data\Malwarebytes
2012-08-17 03:58:34 22344 —-a-w- c:\windows\system32\drivers\mbam.sys
2012-08-17 03:58:33 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2012-08-16 20:25:55 ——– d—–w- c:\program files\Trend Micro
2012-08-16 19:29:04 ——– d—–w- c:\documents and settings\administrator\local settings\application data\tjnet
2012-08-16 19:26:20 49152 —-a-w- c:\windows\system32\ChCfg.exe
2012-08-16 19:25:45 4122368 —-a-r- c:\windows\system32\drivers\alcxwdm.sys
2012-08-16 19:24:23 ——– d—–w- c:\program files\Realtek AC97
2012-08-16 19:24:21 10528768 —-a-w- c:\windows\system32\RTLCPL.exe
2012-08-16 19:24:12 577536 —-a-w- c:\windows\soundman.exe
2012-08-16 19:24:12 18804736 —-a-w- c:\windows\system32\alsndmgr.cpl
2012-08-16 19:24:10 147456 —-a-w- c:\windows\system32\RtlCPAPI.dll
2012-08-16 19:24:08 315392 —-a-w- c:\windows\alcupd.exe
2012-08-16 19:24:08 217088 —-a-w- c:\windows\Alcrmv.exe
2012-08-16 19:16:15 ——– d—–w- c:\documents and settings\administrator\local settings\application data\magicJack
2012-08-16 19:16:08 ——– d—–w- c:\documents and settings\all users\application data\magicJack
2012-08-16 19:13:48 ——– d—–w- c:\documents and settings\administrator\application data\mjusbsp
2012-08-16 13:32:59 ——– d—–w- c:\program files\oDesk
2012-08-16 13:32:54 ——– d—–w- c:\documents and settings\administrator\local settings\application data\oDesk
2012-08-16 13:06:12 ——– d—–w- c:\program files\OpenOffice.org 3
2012-08-16 12:34:59 ——– d—–w- c:\program files\uTorrent
2012-08-16 12:33:10 ——– d—–w- c:\documents and settings\administrator\application data\uTorrent
2012-08-16 12:19:02 712704 —-a-w- c:\windows\system32\windowscodecs.dll
2012-08-16 12:18:27 178688 —-a-w- c:\windows\system32\unrar.dll
2012-08-16 12:18:07 ——– d—–w- c:\program files\K-Lite Codec Pack
2012-08-16 12:08:10 ——– d—–w- c:\windows\system32\Adobe
.
==================== Find3M ====================
.
2012-08-16 07:49:57 70344 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-08-16 07:49:57 426184 —-a-w- c:\windows\system32\FlashPlayerApp.exe
2012-08-16 04:27:37 107132 —-a-w- c:\windows\UninstallFirefox.exe
2012-08-16 04:25:54 107132 —-a-w- c:\windows\UninstallThunderbird.exe
2012-07-03 16:21:53 721000 —-a-w- c:\windows\system32\drivers\aswSnx.sys
2012-07-03 16:21:32 41224 —-a-w- c:\windows\avastSS.scr
2012-05-25 10:06:00 1706640 —-a-w- c:\windows\RtlExUpd.dll
.
============= FINISH: 10:24:51.14 ===============
.
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
.
DDS (Ver_2011-08-26.01)
.
Microsoft Windows XP Professional
Boot Device: \Device\HarddiskVolume1
Install Date: 8/16/2012 12:29:06 PM
System Uptime: 8/18/2012 9:30:14 AM (1 hours ago)
.
Motherboard:
http://www.abit.com.tw | | SG72(SIS 661FX-964L)
Processor: Intel® Pentium® 4 CPU 2.40GHz | Socket 478 | 2405/133mhz
.
==== Disk Partitions =========================
.
A: is Removable
C: is FIXED (NTFS) - 37 GiB total, 32.568 GiB free.
D: is CDROM ()
E: is CDROM (CDFS)
F: is Removable
G: is CDROM ()
.
==== Disabled Device Manager Items =============
.
Class GUID: {4D36E97E-E325-11CE-BFC1-08002BE10318}
Description: Video Controller (VGA Compatible)
Device ID: PCI\VEN_1039&DEV_6330&SUBSYS_1806147B&REV_00\4&1AFFAA3D&0&0008
Manufacturer:
Name: Video Controller (VGA Compatible)
PNP Device ID: PCI\VEN_1039&DEV_6330&SUBSYS_1806147B&REV_00\4&1AFFAA3D&0&0008
Service:
.
Class GUID: {4D36E97E-E325-11CE-BFC1-08002BE10318}
Description: Ethernet Controller
Device ID: PCI\VEN_10EC&DEV_8169&SUBSYS_434E1371&REV_10\3&61AAA01&0&48
Manufacturer:
Name: Ethernet Controller
PNP Device ID: PCI\VEN_10EC&DEV_8169&SUBSYS_434E1371&REV_10\3&61AAA01&0&48
Service:
.
==== System Restore Points ===================
.
No restore point in system.
.
==== Installed Programs ======================
.
µTorrent
Adobe Flash Player 11 Plugin
Adobe Reader X (10.1.4)
Adobe Shockwave Player 11.6
Attribute Changer 5.23
avast! Free Antivirus
CCleaner
Google Update Helper
High Definition Audio Driver Package - KB888111
Hotfix for Windows XP (KB915865)
J2SE Runtime Environment 5.0 Update 5
K-Lite Codec Pack 9.1.0 (Full)
magicJack
Malwarebytes Anti-Malware version 1.62.0.1300
Microsoft .NET Framework 2.0
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30411
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
MozBackup 1.4.3
Mozilla Firefox 14.0.1 (x86 en-US)
Mozilla Maintenance Service
Mozilla Thunderbird (1.5)
oDesk Team
OpenOffice.org 3.4
Realtek AC'97 Audio
Realtek High Definition Audio Driver
Skype™ 5.10
SMART BRO
swMSM
WinRAR 4.11 (32-bit)
Yahoo! Messenger
.
==== Event Viewer Messages From Past Week ========
.
8/17/2012 1:47:21 PM, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the Windows Image Acquisition (WIA) service to connect.
8/17/2012 1:47:21 PM, error: Service Control Manager [7000] - The Windows Image Acquisition (WIA) service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
8/17/2012 1:08:52 PM, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the MBAMService service to connect.
8/17/2012 1:08:52 PM, error: Service Control Manager [7000] - The MBAMService service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
8/16/2012 6:11:18 PM, error: NetBT [4311] - Initialization failed because the driver device could not be created.
8/16/2012 6:09:39 PM, error: System Error [1003] - Error code 100000d1, parameter1 007300c5, parameter2 00000005, parameter3 00000000, parameter4 f766ece7.
8/16/2012 4:17:19 PM, error: System Error [1003] - Error code 1000000a, parameter1 00000008, parameter2 00000002, parameter3 00000000, parameter4 804f0adc.
8/16/2012 4:08:14 PM, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the Application Layer Gateway Service service to connect.
8/16/2012 4:08:14 PM, error: Service Control Manager [7000] - The Application Layer Gateway Service service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
8/16/2012 3:56:41 PM, error: atapi [9] - The device, \Device\Ide\IdePort0, did not respond within the timeout period.
8/16/2012 3:13:56 PM, error: Service Control Manager [7023] - The Windows Firewall/Internet Connection Sharing (ICS) service terminated with the following error: Access is denied.
8/16/2012 2:37:02 PM, error: Service Control Manager [7034] - The Google Update Service (gupdate) service terminated unexpectedly. It has done this 1 time(s).
8/16/2012 12:29:27 PM, error: Setup [60055] - Windows Setup encountered non-fatal errors during installation. Please check the setuperr.log found in your Windows directory for more information.
8/16/2012 1:29:46 PM, error: System Error [1003] - Error code 000000f4, parameter1 00000003, parameter2 8294f880, parameter3 8294f9f4, parameter4 805fa158.
8/16/2012 1:23:18 PM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service EventSystem with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}
8/16/2012 1:17:57 PM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service MSIServer with arguments "" in order to run the server: {000C101C-0000-0000-C000-000000000046}
8/16/2012 1:17:45 PM, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: AFD Fips intelppm IPSec MRxSmb NetBIOS NetBT RasAcd Rdbss Tcpip
8/16/2012 1:17:45 PM, error: Service Control Manager [7001] - The TCP/IP NetBIOS Helper service depends on the AFD service which failed to start because of the following error: A device attached to the system is not functioning.
8/16/2012 1:17:45 PM, error: Service Control Manager [7001] - The IPSEC Services service depends on the IPSEC driver service which failed to start because of the following error: A device attached to the system is not functioning.
8/16/2012 1:17:45 PM, error: Service Control Manager [7001] - The DNS Client service depends on the TCP/IP Protocol Driver service which failed to start because of the following error: A device attached to the system is not functioning.
8/16/2012 1:17:45 PM, error: Service Control Manager [7001] - The DHCP Client service depends on the NetBios over Tcpip service which failed to start because of the following error: A device attached to the system is not functioning.
.
==== End Of File ===========================
MGADiag Logs
Diagnostic Report (1.9.0027.0):
—————————————–
Windows Validation Data–>
Validation Status: Invalid Product Key
Validation Code: 8
Cached Validation Code: N/A
Windows Product Key: *****-*****
Windows Product Key Hash:
Windows Product ID: 55274-640-9138331-23900
Windows Product ID Type: 1
Windows License Type: Volume
Windows OS version: 5.1.2600.2.00010100.2.0.pro
ID: {DB0F5CFC-9287-41AC-82AE-5EF1E4EB23E8}(3)
Is Admin: Yes
TestCab: 0x0
LegitcheckControl ActiveX: Registered, 1.4.389.0
Signed By: N/A, hr = 0x80096010
Product Name: N/A
Architecture: N/A
Build lab: N/A
TTS Error: N/A
Validation Diagnostic: 025D1FF3-230-1
Resolution Status: N/A
Vista WgaER Data–>
ThreatID(s): N/A
Version: N/A
Windows XP Notifications Data–>
Cached Result: N/A, hr = 0x80070002
File Exists: No
Version: N/A, hr = 0x80070002
WgaTray.exe Signed By: N/A, hr = 0x80070002
WgaLogon.dll Signed By: N/A, hr = 0x80070002
OGA Notifications Data–>
Cached Result: N/A, hr = 0x80070002
Version: N/A, hr = 0x80070002
OGAExec.exe Signed By: N/A, hr = 0x80070002
OGAAddin.dll Signed By: N/A, hr = 0x80070002
OGA Data–>
Office Status: 109 N/A
OGA Version: N/A, 0x80070002
Signed By: N/A, hr = 0x80070002
Office Diagnostics: 025D1FF3-230-1
Browser Data–>
Proxy settings: N/A
User Agent: Mozilla/4.0 (compatible; MSIE 6.0; Win32)
Default Browser: C:\Program Files\Mozilla Firefox\firefox.exe
Download signed ActiveX controls: Prompt
Download unsigned ActiveX controls: Disabled
Run ActiveX controls and plug-ins: Allowed
Initialize and script ActiveX controls not marked as safe: Disabled
Allow scripting of Internet Explorer Webbrowser control: Disabled
Active scripting: Allowed
Script ActiveX controls marked as safe for scripting: Allowed
File Scan Data–>
Other data–>
Office Details: {DB0F5CFC-9287-41AC-82AE-5EF1E4EB23E8}1.9.0027.05.1.2600.2.00010100.2.0.prox32*****-*****-*****-*****-QG4JD55274-640-9138331-239001S-1-5-21-1292428093-1547161642-1801674531SiS Technology Inc.SiS661FX + SiS964Phoenix Technologies, LTD6.00 PG20050406000000.000000+000EAC333070184A05304090409Malay Peninsula Standard Time(GMT+08:00)01 109
Licensing Data–>
N/A
Windows Activation Technologies–>
N/A
HWID Data–>
N/A
OEM Activation 1.0 Data–>
BIOS string matches: yes
Marker string from BIOS: 1B9F7:Elitegroup Computer Systems Co Ltd
Marker string from OEMBIOS.DAT: N/A, hr = 0x80004005
OEM Activation 2.0 Data–>
N/A