This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Can Someone Analysis My Log

17 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello, I'm new and would appreciate your help. Thanks.


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 17:24:44, on 10/23/2008
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\VTTimer.exe
C:\WINDOWS\System32\VTtrayp.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\System32\rundll32.exe
C:\Program Files\Creative\Sync Manager Unicode\CTSyncU.exe
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
C:\Program Files\Messenger\MSMSGS.EXE
C:\Program Files\DAEMON Tools\daemon.exe
C:\Program Files\Save\Save.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpohmr08.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
C:\Program Files\Zone Labs\ZoneAlarm\zapro.exe
C:\WINDOWS\System32\CTsvcCDA.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\Bin\hpoSTS08.exe
C:\WINDOWS\System32\wpabaln.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Vuze\Azureus.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

O3 - Toolbar: Ask Toolbar - {F0D4B239-DA4B-4daf-81E4-DFEE4931A4AA} - C:\Program Files\AskSBar\bar\1.bin\ASKSBAR.DLL
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
O4 - HKLM\..\Run: [VTTrayp] VTtrayp.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [CTRegRun] C:\WINDOWS\CTRegRun.EXE
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [d8b20a17] rundll32.exe "C:\WINDOWS\System32\nuubtsms.dll",b
O4 - HKCU\..\Run: [CTSyncU.exe] "C:\Program Files\Creative\Sync Manager Unicode\CTSyncU.exe"
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\MSMSGS.EXE" /background
O4 - HKCU\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKCU\..\Run: [WhenUSave] "C:\Program Files\Save\Save.exe"
O4 - Global Startup: hp psc 1000 series.lnk = ?
O4 - Global Startup: hpoddt01.exe.lnk = ?
O4 - Global Startup: ZoneAlarm Pro.lnk = C:\Program Files\Zone Labs\ZoneAlarm\zapro.exe
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O20 - AppInit_DLLs: wdpite.dll
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs Inc. - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

–
End of file - 3760 bytes
Hello

Please run the MGA Diagnostic Tool and post back the report it shall produce:
  • Download MGADiag to your desktop.
  • Double-click on MGADiag.exe to launch the program
  • Click "Continue"
  • Ensure that the "Windows" tab is selected (it should be by default).
  • Click the "Copy" button to copy the MGA Diagnostic Report to the Windows clipboard.
  • Paste the MGA Diagnostic Report back here in your next reply.

Hello

Please run the MGA Diagnostic Tool and post back the report it shall produce:

  • Download MGADiag to your desktop.
  • Double-click on MGADiag.exe to launch the program
  • Click "Continue"
  • Ensure that the "Windows" tab is selected (it should be by default).
  • Click the "Copy" button to copy the MGA Diagnostic Report to the Windows clipboard.
  • Paste the MGA Diagnostic Report back here in your next reply.



Hello Rorschach112, thanks for your response.

I downloaded MGADiag and followed your instructions. I clicked the copy button, but where do I find the windows clipboard ? so that I can paste the MGA Diagnostic Report here.
O.k., I got it.


Diagnostic Report (1.7.0095.0):
—————————————–
WGA Data–>
Validation Status: Not Activated
Validation Code: 1
Online Validation Code: N/A
Cached Validation Code: N/A
Windows Product Key: *****-*****-6VDYH-2PRHY-GGHQQ
Windows Product Key Hash: LvnixVHP+7leZupYyTf5FBCbHIg=
Windows Product ID: 55277-006-3288617-21295
Windows Product ID Type: 5
Windows License Type: Retail
Windows OS version: 5.1.2600.2.00010300.1.0.hom
CSVLK Server: N/A
CSVLK PID: N/A
ID: {E6594833-497A-4F31-B35C-40DE3DFF2609}(3)
Is Admin: Yes
TestCab: 0x0
WGA Version: N/A, hr = 0x80070002
Signed By: N/A, hr = 0x80070002
Product Name: N/A
Architecture: N/A
Build lab: N/A
TTS Error: N/A
Validation Diagnostic: 025D1FF3-171-1_025D1FF3-179-2_025D1FF3-199-3
Resolution Status: N/A

WgaER Data–>
ThreatID(s): N/A
Version: N/A

WGA Notifications Data–>
Cached Result: N/A, hr = 0x80070002
File Exists: No
Version: N/A, hr = 0x80070002
WgaTray.exe Signed By: N/A, hr = 0x80070002
WgaLogon.dll Signed By: N/A, hr = 0x80070002

OGA Notifications Data–>
Cached Result: N/A, hr = 0x80070002
Version: N/A, hr = 0x80070002
WGATray.exe Signed By: N/A, hr = 0x80070002
OGAAddin.dll Signed By: N/A, hr = 0x80070002

OGA Data–>
Office Status: 109 N/A
OGA Version: N/A, 0x80070002
Signed By: N/A, hr = 0x80070002
Office Diagnostics: B4D0AA8B-543-80070002_025D1FF3-171-1_025D1FF3-179-2_025D1FF3-199-3

Browser Data–>
Proxy settings: N/A
User Agent: Mozilla/4.0 (compatible; MSIE 6.0; Win32)
Default Browser: C:\Program Files\Mozilla Firefox\firefox.exe
Download signed ActiveX controls: Prompt
Download unsigned ActiveX controls: Disabled
Run ActiveX controls and plug-ins: Allowed
Initialize and script ActiveX controls not marked as safe: Disabled
Allow scripting of Internet Explorer Webbrowser control: Disabled
Active scripting: Allowed
Script ActiveX controls marked as safe for scripting: Allowed

File Scan Data–>

Other data–>
Office Details: {E6594833-497A-4F31-B35C-40DE3DFF2609}1.7.0095.05.1.2600.2.00010300.1.0.homx32*****-*****-*****-*****-GGHQQ55277-006-3288617-212955S-1-5-21-796845957-484763869-682003330P4M80PAWRDACPIPhoenix Technologies, LTD6.00 PG20070609******.******+***99033FF701842E6304090409Eastern Standard Time(GMT-05:00)03 109
I activated my windows and repeated your instructions.

Diagnostic Report (1.7.0095.0):
—————————————–
WGA Data–>
Validation Status: Validation Control not Installed
Validation Code: 0
Online Validation Code: N/A
Cached Validation Code: N/A
Windows Product Key: *****-*****-6VDYH-2PRHY-GGHQQ
Windows Product Key Hash: LvnixVHP+7leZupYyTf5FBCbHIg=
Windows Product ID: 55277-006-3288617-21295
Windows Product ID Type: 5
Windows License Type: Retail
Windows OS version: 5.1.2600.2.00010300.1.0.hom
CSVLK Server: N/A
CSVLK PID: N/A
ID: {E6594833-497A-4F31-B35C-40DE3DFF2609}(3)
Is Admin: Yes
TestCab: 0x0
WGA Version: N/A, hr = 0x80070002
Signed By: N/A, hr = 0x80070002
Product Name: N/A
Architecture: N/A
Build lab: N/A
TTS Error: N/A
Validation Diagnostic: 025D1FF3-171-1
Resolution Status: N/A

WgaER Data–>
ThreatID(s): N/A
Version: N/A

WGA Notifications Data–>
Cached Result: N/A, hr = 0x80070002
File Exists: No
Version: N/A, hr = 0x80070002
WgaTray.exe Signed By: N/A, hr = 0x80070002
WgaLogon.dll Signed By: N/A, hr = 0x80070002

OGA Notifications Data–>
Cached Result: N/A, hr = 0x80070002
Version: N/A, hr = 0x80070002
WGATray.exe Signed By: N/A, hr = 0x80070002
OGAAddin.dll Signed By: N/A, hr = 0x80070002

OGA Data–>
Office Status: 109 N/A
OGA Version: N/A, 0x80070002
Signed By: N/A, hr = 0x80070002
Office Diagnostics: B4D0AA8B-543-80070002_025D1FF3-171-1

Browser Data–>
Proxy settings: N/A
User Agent: Mozilla/4.0 (compatible; MSIE 6.0; Win32)
Default Browser: C:\Program Files\Mozilla Firefox\firefox.exe
Download signed ActiveX controls: Prompt
Download unsigned ActiveX controls: Disabled
Run ActiveX controls and plug-ins: Allowed
Initialize and script ActiveX controls not marked as safe: Disabled
Allow scripting of Internet Explorer Webbrowser control: Disabled
Active scripting: Allowed
Script ActiveX controls marked as safe for scripting: Allowed

File Scan Data–>

Other data–>
Office Details: {E6594833-497A-4F31-B35C-40DE3DFF2609}1.7.0095.05.1.2600.2.00010300.1.0.homx32*****-*****-*****-*****-GGHQQ55277-006-3288617-212955S-1-5-21-796845957-484763869-682003330P4M80PAWRDACPIPhoenix Technologies, LTD6.00 PG20070609******.******+***99033FF701842E6304090409Eastern Standard Time(GMT-05:00)03 109
I believe I have validated my windows.


Diagnostic Report (1.7.0095.0):
—————————————–
WGA Data–>
Validation Status: Genuine
Validation Code: 0
Online Validation Code: N/A
Cached Validation Code: N/A
Windows Product Key: *****-*****-6VDYH-2PRHY-GGHQQ
Windows Product Key Hash: LvnixVHP+7leZupYyTf5FBCbHIg=
Windows Product ID: 55277-006-3288617-21295
Windows Product ID Type: 5
Windows License Type: Retail
Windows OS version: 5.1.2600.2.00010300.1.0.hom
CSVLK Server: N/A
CSVLK PID: N/A
ID: {E6594833-497A-4F31-B35C-40DE3DFF2609}(3)
Is Admin: Yes
TestCab: 0x0
WGA Version: Registered, 1.7.69.2
Signed By: Microsoft
Product Name: N/A
Architecture: N/A
Build lab: N/A
TTS Error: N/A
Validation Diagnostic: 025D1FF3-171-1
Resolution Status: N/A

WgaER Data–>
ThreatID(s): N/A
Version: N/A

WGA Notifications Data–>
Cached Result: N/A, hr = 0x80070002
File Exists: No
Version: N/A, hr = 0x80070002
WgaTray.exe Signed By: N/A, hr = 0x80070002
WgaLogon.dll Signed By: N/A, hr = 0x80070002

OGA Notifications Data–>
Cached Result: N/A, hr = 0x80070002
Version: N/A, hr = 0x80070002
WGATray.exe Signed By: N/A, hr = 0x80070002
OGAAddin.dll Signed By: N/A, hr = 0x80070002

OGA Data–>
Office Status: 109 N/A
OGA Version: Registered, 1.6.28.0
Signed By: Microsoft
Office Diagnostics: B4D0AA8B-543-80070002_025D1FF3-171-1

Browser Data–>
Proxy settings: N/A
User Agent: Mozilla/4.0 (compatible; MSIE 6.0; Win32)
Default Browser: C:\Program Files\Mozilla Firefox\firefox.exe
Download signed ActiveX controls: Prompt
Download unsigned ActiveX controls: Disabled
Run ActiveX controls and plug-ins: Allowed
Initialize and script ActiveX controls not marked as safe: Disabled
Allow scripting of Internet Explorer Webbrowser control: Disabled
Active scripting: Allowed
Script ActiveX controls marked as safe for scripting: Allowed

File Scan Data–>

Other data–>
Office Details: {E6594833-497A-4F31-B35C-40DE3DFF2609}1.7.0095.05.1.2600.2.00010300.1.0.homx32*****-*****-*****-*****-GGHQQ55277-006-3288617-212955S-1-5-21-796845957-484763869-682003330P4M80PAWRDACPIPhoenix Technologies, LTD6.00 PG20070609******.******+***99033FF701842E6304090409Eastern Standard Time(GMT-05:00)03 109
Hello

Disable resident protections (Antivirus…); you'll re-enable them after the scan

Download Lop S&D < here

Double-click Lop S&D.exe
Choose the language, then choose Option 1 (Search)
Wait till the end of the scan
Post the log which is created: (%SystemDrive%\lopR.txt)
——————–\\ Lop S&D 4.2.4-7 XP/Vista

Microsoft Windows XP Home Edition ( v5.1.2600 ) Service Pack 1
X86-based PC ( Multiprocessor Free : Intel® Pentium® 4 CPU 2.60GHz )
BIOS : Phoenix - AwardBIOS v6.00PG
USER : Owner ( Administrator )
BOOT : Normal boot
A:\ (USB)
C:\ (Local Disk) - NTFS - Total : 149 Go Free : 80 Go
D:\ (CD or DVD)
E:\ (CD or DVD)
F:\ (CD or DVD)

"C:\Lop SD" ( MAJ : 23-10-2008|23:15 )
Option : [1] ( Fri 10/24/2008|22:19 )

——————–\\ Listing folders in APPLIC~1

[10/22/2008|21:09] C:\DOCUME~1\ALLUSE~1\APPLIC~1\1Click DVD Copy
[10/21/2008|17:38] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Ahead
[10/02/2008|23:59] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Azureus
[10/02/2008|20:53] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Broderbund LLC
[10/02/2008|21:25] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Creative
[10/22/2008|22:16] C:\DOCUME~1\ALLUSE~1\APPLIC~1\DVD Shrink
[10/03/2008|13:28] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Microsoft
[10/24/2008|20:33] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Nero
[10/23/2008|20:13] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Office Genuine Advantage
[10/22/2008|21:49] C:\DOCUME~1\ALLUSE~1\APPLIC~1\SlySoft
[10/24/2008|17:03] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Windows Genuine Advantage

[10/02/2008|20:27] C:\DOCUME~1\DEFAUL~1\APPLIC~1\Microsoft

[10/02/2008|20:32] C:\DOCUME~1\LOCALS~1\APPLIC~1\Microsoft

[10/02/2008|20:32] C:\DOCUME~1\NETWOR~1\APPLIC~1\Microsoft

[10/02/2008|22:14] C:\DOCUME~1\Owner\APPLIC~1\Adobe
[10/21/2008|18:16] C:\DOCUME~1\Owner\APPLIC~1\Ahead
[10/24/2008|20:26] C:\DOCUME~1\Owner\APPLIC~1\Azureus
[10/14/2008|14:04] C:\DOCUME~1\Owner\APPLIC~1\Creative
[10/15/2008|13:06] C:\DOCUME~1\Owner\APPLIC~1\Hewlett-Packard
[10/02/2008|20:32] C:\DOCUME~1\Owner\APPLIC~1\Identities
[10/02/2008|22:14] C:\DOCUME~1\Owner\APPLIC~1\Macromedia
[10/10/2008|17:36] C:\DOCUME~1\Owner\APPLIC~1\Microsoft
[10/02/2008|21:05] C:\DOCUME~1\Owner\APPLIC~1\Mozilla
[10/03/2008|13:35] C:\DOCUME~1\Owner\APPLIC~1\TotalRecorder
[10/22/2008|21:46] C:\DOCUME~1\Owner\APPLIC~1\Vso

——————–\\ Scheduled Tasks located in C:\WINDOWS\Tasks

[10/15/2008 13:06][–a——] C:\WINDOWS\tasks\WebReg 20081015130630.job
[10/15/2008 13:06][–a——] C:\WINDOWS\tasks\FRU Task #Hewlett-Packard#hp psc 1200 series#1222996893.job
[10/24/2008 20:27][–ah—–] C:\WINDOWS\tasks\SA.DAT
[03/31/2003 08:00][-r-h—–] C:\WINDOWS\tasks\desktop.ini

——————–\\ Listing Folders in C:\Program Files

[10/02/2008|23:58] C:\Program Files\AskSBar
[10/02/2008|22:33] C:\Program Files\Common Files
[10/02/2008|20:25] C:\Program Files\ComPlus Applications
[10/02/2008|21:33] C:\Program Files\Creative
[10/02/2008|21:29] C:\Program Files\Creative Installation Information
[10/10/2008|14:45] C:\Program Files\DAEMON Tools
[10/10/2008|14:48] C:\Program Files\DaemonTools_WhenUSave_Installer
[10/02/2008|20:50] C:\Program Files\Driver
[10/03/2008|13:13] C:\Program Files\DVD Decrypter
[10/03/2008|13:08] C:\Program Files\DVD Shrink
[10/10/2008|19:58] C:\Program Files\FLV Player
[10/02/2008|21:17] C:\Program Files\Hewlett-Packard
[10/03/2008|13:33] C:\Program Files\HighCriteria
[10/02/2008|22:09] C:\Program Files\InstallShield Installation Information
[10/14/2008|11:36] C:\Program Files\Internet Explorer
[10/14/2008|11:42] C:\Program Files\Messenger
[10/02/2008|20:28] C:\Program Files\microsoft frontpage
[10/14/2008|11:36] C:\Program Files\Movie Maker
[10/24/2008|20:43] C:\Program Files\Mozilla Firefox
[10/02/2008|20:24] C:\Program Files\MSN
[10/02/2008|20:24] C:\Program Files\MSN Gaming Zone
[10/02/2008|22:33] C:\Program Files\Nero
[10/21/2008|17:46] C:\Program Files\Nero 7.10.1.0
[10/14/2008|11:36] C:\Program Files\NetMeeting
[10/02/2008|20:24] C:\Program Files\Online Services
[10/14/2008|11:36] C:\Program Files\Outlook Express
[10/02/2008|20:50] C:\Program Files\Realtek AC97
[10/02/2008|20:49] C:\Program Files\S3
[10/10/2008|19:45] C:\Program Files\Save
[10/22/2008|21:47] C:\Program Files\SlySoft
[10/03/2008|13:16] C:\Program Files\SmitfraudFix
[10/03/2008|18:14] C:\Program Files\Total Video Converter
[10/03/2008|13:26] C:\Program Files\Total.Recorder.Pro.7.0.+3.addons+serials
[10/23/2008|17:24] C:\Program Files\Trend Micro
[10/02/2008|20:32] C:\Program Files\Uninstall Information
[10/02/2008|20:46] C:\Program Files\VIA
[10/03/2008|12:56] C:\Program Files\Vuze
[10/21/2008|14:40] C:\Program Files\Windows Media Player
[10/14/2008|11:36] C:\Program Files\Windows NT
[10/04/2008|20:10] C:\Program Files\WindowsUpdate
[10/02/2008|20:28] C:\Program Files\xerox
[10/02/2008|20:57] C:\Program Files\Zone Labs

——————–\\ Listing Folders in C:\Program Files\Common Files

[10/24/2008|20:35] C:\Program Files\Common Files\Ahead
[10/02/2008|21:29] C:\Program Files\Common Files\Creative
[10/02/2008|21:10] C:\Program Files\Common Files\Hewlett-Packard
[10/02/2008|21:30] C:\Program Files\Common Files\InstallShield
[10/02/2008|20:32] C:\Program Files\Common Files\Microsoft Shared
[10/02/2008|20:25] C:\Program Files\Common Files\MSSoap
[10/03/2008|04:18] C:\Program Files\Common Files\ODBC
[10/02/2008|20:25] C:\Program Files\Common Files\Services
[10/03/2008|04:18] C:\Program Files\Common Files\SpeechEngines
[10/14/2008|11:36] C:\Program Files\Common Files\System

——————–\\ Process

( 35 Processes )

… OK !

——————–\\ Searching with S_Lop

No Lop folder found !

——————–\\ Searching for Lop Files - Folders

No Lop folder found !

——————–\\ Searching within the Registry

….. OK !

——————–\\ Checking the Hosts file

Hosts file CLEAN


——————–\\ Searching for hidden files with Catchme

catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-10-24 22:23:05
Windows 5.1.2600 Service Pack 1 NTFS
scanning hidden processes …
scanning hidden files …
scan completed successfully
hidden processes: 0
hidden files: 0

——————–\\ Searching for other infections

C:\WINDOWS\system32\NUvDJRqr.ini
C:\WINDOWS\system32\NUvDJRqr.ini2
==> VUNDO <==

——————–\\ Cracks & Keygens ..

C:\DOCUME~1\Owner\Application Data\Azureus\torrents\1_CLICK_DVD_Copy_5_4_3_8_(NEW)+crack.torrent
C:\DOCUME~1\Owner\Application Data\Azureus\torrents\Nero 7 Ultra Edition Enhanced XP & Vista + Keygen [mininova].torrent
C:\DOCUME~1\Owner\Application Data\Azureus\torrents\[isoHunt] Norton Anti Virus 2008 Incl Keygens Vista Compatible.torrent
C:\DOCUME~1\Owner\Recent\1_CLICK_DVD_Copy_5_4_3_8_(NEW)+crack.lnk
C:\DOCUME~1\Owner\Recent\Nero 7 Ultra Edition Enhanced XP & Vista + Keygen [mininova].lnk
C:\DOCUME~1\Owner\Recent\Nero 7 Ultra Edition Enhanced XP & Vista + Keygen.lnk
C:\DOCUME~1\Owner\Recent\[isoHunt] Norton Anti Virus 2008 Incl Keygens Vista Compatible.lnk


[F:776][D:38]-> C:\DOCUME~1\Owner\LOCALS~1\Temp
[F:46][D:0]-> C:\DOCUME~1\Owner\Cookies
[F:844][D:4]-> C:\DOCUME~1\Owner\LOCALS~1\TEMPOR~1\content.IE5

1 - "C:\Lop SD\LopR_1.txt" - Fri 10/24/2008|22:17 - Option : [1]
2 - "C:\Lop SD\LopR_2.txt" - Fri 10/24/2008|22:24 - Option : [1]

——————–\\ Scan completed at 22:24:40
You got infected because you downloaded cracks

Please download the OTMoveIt3 by OldTimer or from here.
  • Save it to your desktop.
  • Please double-click OTMoveIt3.exe to run it. (Note: If you are running on Vista, right-click on the file and choose Run As Administrator).
  • Copy the lines in the codebox below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):

    :Processes
    explorer.exe
    
    :Services
    
    :Reg
    
    :Files
    C:\Program Files\Total.Recorder.Pro.7.0.+3.addons+serials
    C:\WINDOWS\system32\NUvDJRqr.ini
    C:\WINDOWS\system32\NUvDJRqr.ini2
    C:\DOCUME~1\Owner\Application Data\Azureus\torrents\1_CLICK_DVD_Copy_5_4_3_8_(NEW)+crack.torrent
    C:\DOCUME~1\Owner\Application Data\Azureus\torrents\Nero 7 Ultra Edition Enhanced XP & Vista + Keygen [mininova].torrent
    C:\DOCUME~1\Owner\Application Data\Azureus\torrents\[isoHunt] Norton Anti Virus 2008 Incl Keygens Vista Compatible.torrent
    C:\DOCUME~1\Owner\Recent\1_CLICK_DVD_Copy_5_4_3_8_(NEW)+crack.lnk
    C:\DOCUME~1\Owner\Recent\Nero 7 Ultra Edition Enhanced XP & Vista + Keygen [mininova].lnk
    C:\DOCUME~1\Owner\Recent\Nero 7 Ultra Edition Enhanced XP & Vista + Keygen.lnk
    C:\DOCUME~1\Owner\Recent\[isoHunt] Norton Anti Virus 2008 Incl Keygens Vista Compatible.lnk
    
    :Commands
    [purity]
    [emptytemp]
    [start explorer]
    [Reboot]
  • Return to OTMoveIt3, right click in the "Paste Instructions for Items to be Moved" window (under the yellow bar) and choose Paste.
  • Click the red Moveit! button.
  • Copy everything in the Results window (under the green bar) to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it in your next reply.
  • Close OTMoveIt3
Note: If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes. In this case, after the reboot, open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTMoveIt\MovedFiles folder, and open the newest .log file present, and copy/paste the contents of that document back here in your next post.




Download OTScanIt2.exe to your Desktop and double-click on it to extract the files. It will create a folder named OTScanIt2 on your desktop.
  • Open the OTScanIt2 folder and double-click on OTScanIt.exe to start the program.
  • Under File Age at the top, change it from 30 days to 90 days
  • Under Additional Scans check the boxes beside Reg - App Paths, Reg - Desktop Components, Reg - Disabled MS Config Items, Reg - File Associations, Reg - Protocol Filters, Reg - Protocol Handlers, File - Lop Check, File - Purity Scan, Files - Signature Check, and Evnt - EventViewer Logs ( Last 10 Errors).
  • Under Rootkit Search change it to Yes
  • Now click the Run Scan button on the toolbar.
  • When the scan is complete Notepad will open with the report file loaded in it.
  • Click the Format menu and make sure that Wordwrap is not checked. If it is then click on it to uncheck it.
Use the Add Reply button and post the information back here in an attachment. I will review it when it comes in. The last line is < End of Report >, so make sure that is the last line in the attached report.


Make sure you attach the report in your reply. If it is too big to upload, then zip the text file and upload it that way
========== PROCESSES ========== Process explorer.exe killed successfully. ========== SERVICES/DRIVERS ========== ========== REGISTRY ========== ========== FILES ========== C:\Program Files\Total.Recorder.Pro.7.0.+3.addons+serials moved successfully. C:\WINDOWS\system32\NUvDJRqr.ini moved successfully. C:\WINDOWS\system32\NUvDJRqr.ini2 moved successfully. C:\DOCUME~1\Owner\Application Data\Azureus\torrents\1_CLICK_DVD_Copy_5_4_3_8_(NEW)+crack.torrent moved successfully. C:\DOCUME~1\Owner\Application Data\Azureus\torrents\Nero 7 Ultra Edition Enhanced XP & Vista + Keygen [mininova].torrent moved successfully. C:\DOCUME~1\Owner\Application Data\Azureus\torrents\[isoHunt] Norton Anti Virus 2008 Incl Keygens Vista Compatible.torrent moved successfully. C:\DOCUME~1\Owner\Recent\1_CLICK_DVD_Copy_5_4_3_8_(NEW)+crack.lnk moved successfully. C:\DOCUME~1\Owner\Recent\Nero 7 Ultra Edition Enhanced XP & Vista + Keygen [mininova].lnk moved successfully. C:\DOCUME~1\Owner\Recent\Nero 7 Ultra Edition Enhanced XP & Vista + Keygen.lnk moved successfully. C:\DOCUME~1\Owner\Recent\[isoHunt] Norton Anti Virus 2008 Incl Keygens Vista Compatible.lnk moved successfully. ========== COMMANDS ========== File delete failed. C:\DOCUME~1\Owner\LOCALS~1\Temp\etilqs_Ujdlm6PEu6B3wYFYwAXc scheduled to be deleted on reboot. File delete failed. C:\DOCUME~1\Owner\LOCALS~1\Temp\JETB5C4.tmp scheduled to be deleted on reboot. User's Temp folder emptied. User's Temporary Internet Files folder emptied. User's Internet Explorer cache folder emptied. Local Service Temp folder emptied. File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot. Local Service Temporary Internet Files folder emptied. File delete failed. C:\WINDOWS\temp\ZLT021a5.TMP scheduled to be deleted on reboot. Windows Temp folder emptied. File delete failed. C:\Documents and Settings\Owner\Local Settings\Application Data\Mozilla\Firefox\Profiles\65pm514y.default\Cache\_CACHE_001_ scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Owner\Local Settings\Application Data\Mozilla\Firefox\Profiles\65pm514y.default\Cache\_CACHE_002_ scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Owner\Local Settings\Application Data\Mozilla\Firefox\Profiles\65pm514y.default\Cache\_CACHE_003_ scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Owner\Local Settings\Application Data\Mozilla\Firefox\Profiles\65pm514y.default\Cache\_CACHE_MAP_ scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Owner\Local Settings\Application Data\Mozilla\Firefox\Profiles\65pm514y.default\urlclassifier3.sqlite scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Owner\Local Settings\Application Data\Mozilla\Firefox\Profiles\65pm514y.default\XUL.mfl scheduled to be deleted on reboot. FireFox cache emptied. Temp folders emptied. Explorer started successfully OTMoveIt3 by OldTimer - Version 1.0.5.0 log created on 10252008_200628 Files moved on Reboot… File move failed. C:\DOCUME~1\Owner\LOCALS~1\Temp\etilqs_Ujdlm6PEu6B3wYFYwAXc scheduled to be moved on reboot. File move failed. C:\DOCUME~1\Owner\LOCALS~1\Temp\JETB5C4.tmp scheduled to be moved on reboot. File move failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be moved on reboot. File move failed. C:\WINDOWS\temp\ZLT021a5.TMP scheduled to be moved on reboot. File move failed. C:\Documents and Settings\Owner\Local Settings\Application Data\Mozilla\Firefox\Profiles\65pm514y.default\Cache\_CACHE_001_ scheduled to be moved on reboot. File move failed. C:\Documents and Settings\Owner\Local Settings\Application Data\Mozilla\Firefox\Profiles\65pm514y.default\Cache\_CACHE_002_ scheduled to be moved on reboot. File move failed. C:\Documents and Settings\Owner\Local Settings\Application Data\Mozilla\Firefox\Profiles\65pm514y.default\Cache\_CACHE_003_ scheduled to be moved on reboot. File move failed. C:\Documents and Settings\Owner\Local Settings\Application Data\Mozilla\Firefox\Profiles\65pm514y.default\Cache\_CACHE_MAP_ scheduled to be moved on reboot. File move failed. C:\Documents and Settings\Owner\Local Settings\Application Data\Mozilla\Firefox\Profiles\65pm514y.default\urlclassifier3.sqlite scheduled to be moved on reboot. File move failed. C:\Documents and Settings\Owner\Local Settings\Application Data\Mozilla\Firefox\Profiles\65pm514y.default\XUL.mfl scheduled to be moved on reboot.

Attachments:

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI