This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] computer is practically dead.

15 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

my computer is so messed up… I probably waited wayyy too long to try and fix it. but I finally got it to boot up, it wouldn't even do that before. but I can only boot it up in safe mode. and sometimes i can't even get on the internet :/

like a year ago i downloaded virus heal… i didn't have any problems at all until maybe 3 months ago, now it's totally corrupted my computer.
help please!




Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 1:17:31 PM, on 1/19/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16762)
Boot mode: Safe mode with network support

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Safari\Safari.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = https://login.live.com/resetpw.srf?lc=1033
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)
O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent
O4 - HKCU\..\Run: [EasyLinkAdvisor] "C:\Program Files\Linksys EasyLink Advisor\LinksysAgent.exe" /startup
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [AIM] C:\PROGRA~1\AIM\aim.exe -cnetwait.odl
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Easy-WebPrint Add To Print List - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html
O8 - Extra context menu item: Easy-WebPrint High Speed Print - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html
O8 - Extra context menu item: Easy-WebPrint Preview - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html
O8 - Extra context menu item: Easy-WebPrint Print - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Print.html
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\PROGRA~1\AIM\aim.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {036F8A56-0BC8-4607-8F98-D3231E6FF5ED} - http://centra01.ccsd.net/SiteRoots/main/In…raUpdaterAx.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1180113720703
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} - http://download.divx.com/player/DivXBrowserPlugin.cab
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe

–
End of file - 5650 bytes
Hello there and welcome

like a year ago i downloaded virus heal…

Was this deliberate ?

OK I will need to start off with a deeper look at your system before I determine what approach to take

To ensure that I get all the information this log will need to be attached (instructions at the end) if it is to large to attach then upload to Mediafire and post the sharing link.

Download OTScanit2 to your Desktop and double-click on it to extract the files. It will create a folder named OTScanIt on your desktop.
  • Close ALL OTHER PROGRAMS.
  • Open the OTScanit folder and double-click on OTScanit.exe to start the program.
  • Check the box that says Scan All Users
  • Check the Radio button for Rootkit check YES
  • Under Additional Scans check the following:
    • File - Lop Check
    • File - Purity Scan
    • Evnt - EventViewer Errors/Warnings (last 10)
  • Now click the Run Scan button on the toolbar.
  • Let it run unhindered until it finishes.
  • When the scan is complete Notepad will open with the report file loaded in it.
  • Click the Format menu and make sure that Wordwrap is not checked. If it is then click on it to uncheck it.
Please attach the log in your next post.

To attach a file, do the following:
  • Click Add Reply
  • Under the reply panel is the Attachments Panel
  • Browse for the attachment file you want to upload, then click the green Upload button
  • Once it has uploaded, click the Manage Current Attachments drop down box
  • Click on [external image: Posted Image] to insert the attachment into your post
no.. i wasn't aware that it was computer killing program.. lol i downloaded the OTScanIt2 but it won't run a scan. I choose all the settings you told me to but once I click the run scan button it just freezes, and I have to pull up the task manager and end task. I did this three times and let it sit for about an hour the last time to see if it would do anything, but didn't. I restarted my computer and tried to run it and it still did the same thing. Maybe it's cause I have to be in safemode? Or probably because my computer is so messed up :/
It should have run in safe mode with no problem. OK lets try a less intrusive programme

Disable resident protections (Antivirus…); you'll re-enable them after the scan

Download Lop S&D < here

Double-click Lop S&D.exe
Choose the language, then choose Option 1 (Search)
Wait till the end of the scan
Post the log which is created: (%SystemDrive%\lopR.txt)
okay here is the log






——————–\\ Lop S&D 4.2.5-0 XP/Vista

Microsoft Windows XP Professional ( v5.1.2600 ) Service Pack 3
X86-based PC ( Uniprocessor Free : Intel® Celeron® CPU 2.40GHz )
BIOS : Phoenix ROM BIOS PLUS Version 1.10 A05
USER : Red Hood ( Administrator )
BOOT : Fail-safe with network boot
C:\ (Local Disk) - NTFS - Total:74 Go (Free:54 Go)
D:\ (CD or DVD)
E:\ (USB)
F:\ (CD or DVD)
G:\ (USB)
H:\ (USB)
I:\ (USB)
J:\ (USB)

"C:\Lop SD" ( MAJ : 19-12-2008|23:40 )
Option : [1] ( Tue 01/20/2009|18:26 )

——————–\\ Listing folders in APPLIC~1

[06/14/2007|11:24] C:\DOCUME~1\ADMINI~1\APPLIC~1\ acccore
[08/13/2007|11:12] C:\DOCUME~1\ADMINI~1\APPLIC~1\ Adobe
[01/18/2009|08:17] C:\DOCUME~1\ADMINI~1\APPLIC~1\ Apple Computer
[06/18/2007|07:03] C:\DOCUME~1\ADMINI~1\APPLIC~1\ CyberLink
[05/25/2007|02:45] C:\DOCUME~1\ADMINI~1\APPLIC~1\ Google
[10/20/2007|01:08] C:\DOCUME~1\ADMINI~1\APPLIC~1\ GTek
[05/22/2007|12:44] C:\DOCUME~1\ADMINI~1\APPLIC~1\ Identities
[05/22/2007|01:23] C:\DOCUME~1\ADMINI~1\APPLIC~1\ Jasc Software Inc
[08/28/2007|02:12] C:\DOCUME~1\ADMINI~1\APPLIC~1\ LimeWire
[05/25/2007|02:03] C:\DOCUME~1\ADMINI~1\APPLIC~1\ Macromedia
[11/15/2007|01:15] C:\DOCUME~1\ADMINI~1\APPLIC~1\ Microsoft
[06/14/2007|11:13] C:\DOCUME~1\ADMINI~1\APPLIC~1\ Mozilla
[11/10/2007|07:08] C:\DOCUME~1\ADMINI~1\APPLIC~1\ Sony Ericsson
[09/22/2007|12:02] C:\DOCUME~1\ADMINI~1\APPLIC~1\ Sun
[12/08/2007|10:49] C:\DOCUME~1\ADMINI~1\APPLIC~1\ Teleca
[06/14/2007|11:30] C:\DOCUME~1\ADMINI~1\APPLIC~1\ Viewpoint

[11/22/2008|12:06] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ {3276BE95_AF08_429F_A64F_CA64CB79BCF6}
[05/07/2008|01:44] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Adobe
[11/04/2008|11:16] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ AOL
[05/08/2008|11:50] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ AOL Downloads
[06/14/2007|11:23] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ AOL OCP
[08/22/2007|10:36] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Apple
[06/14/2007|11:42] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Apple Computer
[05/02/2008|05:55] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ CanonBJ
[05/22/2007|01:22] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ CyberLink
[08/31/2007|03:07] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Google
[10/20/2007|01:06] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ GTek
[01/19/2009|10:52] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Malwarebytes
[11/14/2008|07:29] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ McAfee
[11/14/2008|07:04] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ McAfee.com
[11/14/2008|07:33] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Microsoft
[01/18/2009|11:14] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ TEMP
[11/14/2008|07:09] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Viewpoint
[05/25/2007|09:30] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Windows Genuine Advantage
[12/13/2007|12:45] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ WLInstaller

[10/20/2007|01:08] C:\DOCUME~1\DEFAUL~1\APPLIC~1\ Gtek
[05/22/2007|12:37] C:\DOCUME~1\DEFAUL~1\APPLIC~1\ Microsoft

[12/08/2007|11:06] C:\DOCUME~1\Guest\APPLIC~1\ Gtek
[12/08/2007|11:05] C:\DOCUME~1\Guest\APPLIC~1\ Identities
[12/08/2007|11:05] C:\DOCUME~1\Guest\APPLIC~1\ Microsoft

[05/22/2007|12:44] C:\DOCUME~1\LOCALS~1\APPLIC~1\ Microsoft

[05/22/2007|12:44] C:\DOCUME~1\NETWOR~1\APPLIC~1\ Microsoft

[09/15/2008|11:45] C:\DOCUME~1\REDHOO~1\APPLIC~1\ Adobe
[11/04/2008|11:21] C:\DOCUME~1\REDHOO~1\APPLIC~1\ Aim
[08/07/2008|04:08] C:\DOCUME~1\REDHOO~1\APPLIC~1\ Apple Computer
[06/19/2008|09:44] C:\DOCUME~1\REDHOO~1\APPLIC~1\ Aston
[11/13/2008|05:51] C:\DOCUME~1\REDHOO~1\APPLIC~1\ Canon
[12/09/2007|12:42] C:\DOCUME~1\REDHOO~1\APPLIC~1\ CyberLink
[10/24/2008|12:16] C:\DOCUME~1\REDHOO~1\APPLIC~1\ FrostWire
[12/08/2007|10:30] C:\DOCUME~1\REDHOO~1\APPLIC~1\ Gtek
[12/08/2007|10:30] C:\DOCUME~1\REDHOO~1\APPLIC~1\ Identities
[01/18/2009|07:18] C:\DOCUME~1\REDHOO~1\APPLIC~1\ ijjigame
[08/07/2008|09:54] C:\DOCUME~1\REDHOO~1\APPLIC~1\ LimeWire
[12/19/2008|01:06] C:\DOCUME~1\REDHOO~1\APPLIC~1\ Macromedia
[01/19/2009|10:52] C:\DOCUME~1\REDHOO~1\APPLIC~1\ Malwarebytes
[12/13/2008|12:12] C:\DOCUME~1\REDHOO~1\APPLIC~1\ Microsoft
[01/11/2008|09:27] C:\DOCUME~1\REDHOO~1\APPLIC~1\ MySpace
[01/01/2008|08:49] C:\DOCUME~1\REDHOO~1\APPLIC~1\ SecuROM
[12/08/2007|10:30] C:\DOCUME~1\REDHOO~1\APPLIC~1\ Sony Ericsson
[06/05/2008|11:01] C:\DOCUME~1\REDHOO~1\APPLIC~1\ Sun
[11/14/2008|07:40] C:\DOCUME~1\REDHOO~1\APPLIC~1\ Teleca
[10/24/2008|12:16] C:\DOCUME~1\REDHOO~1\APPLIC~1\ uTorrent

——————–\\ Scheduled Tasks located in C:\WINDOWS\Tasks

[01/19/2009 10:34 AM][–a——] C:\WINDOWS\tasks\RegCure Program Check.job
[01/18/2009 11:12 PM][–a——] C:\WINDOWS\tasks\RegCure.job
[12/12/2008 10:04 PM][–a——] C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[12/16/2008 07:00 AM][–a——] C:\WINDOWS\tasks\McAfee.com Scan for Viruses - My Computer (FAMILY-S6C0SKZX-Administrator).job
[01/19/2009 11:06 AM][–ah—–] C:\WINDOWS\tasks\SA.DAT
[07/16/2003 08:31 AM][-r-h—–] C:\WINDOWS\tasks\desktop.ini

——————–\\ Listing Folders in C:\Program Files

[12/01/2007|01:15] C:\Program Files\ Acoustica MP3 To Wave Converter PLUS
[08/22/2008|02:39] C:\Program Files\ Adobe
[11/04/2008|11:21] C:\Program Files\ AIM
[11/04/2008|11:21] C:\Program Files\ AOD
[08/06/2008|03:46] C:\Program Files\ Apple Software Update
[12/02/2007|12:11] C:\Program Files\ Atari
[08/22/2008|02:41] C:\Program Files\ Audio Converter
[10/13/2008|01:26] C:\Program Files\ Bonjour
[05/22/2007|01:09] C:\Program Files\ Broadcom
[05/22/2007|01:16] C:\Program Files\ Broadcom Management Programs
[05/02/2008|05:50] C:\Program Files\ Canon
[01/19/2009|11:05] C:\Program Files\ Common Files
[05/22/2007|12:34] C:\Program Files\ ComPlus Applications
[05/22/2007|01:30] C:\Program Files\ CyberLink
[05/22/2007|01:22] C:\Program Files\ Dell
[11/24/2007|05:15] C:\Program Files\ DivX
[10/13/2008|12:15] C:\Program Files\ Electronic Arts
[09/01/2007|12:44] C:\Program Files\ Empire Interactive
[08/31/2007|03:14] C:\Program Files\ FirstClass
[10/13/2008|01:02] C:\Program Files\ FrostWire
[09/06/2007|02:50] C:\Program Files\ Google
[01/19/2009|01:09] C:\Program Files\ Hijackthis
[11/14/2008|07:57] C:\Program Files\ InstallShield Installation Information
[05/22/2007|12:58] C:\Program Files\ Intel
[12/13/2008|12:06] C:\Program Files\ Internet Explorer
[11/22/2008|12:06] C:\Program Files\ iPod
[11/22/2008|12:06] C:\Program Files\ iTunes
[10/13/2008|12:14] C:\Program Files\ Jasc Software Inc
[12/18/2008|02:27] C:\Program Files\ Java
[10/13/2008|12:14] C:\Program Files\ LimeWire
[10/20/2007|01:08] C:\Program Files\ Linksys EasyLink Advisor
[10/23/2008|11:58] C:\Program Files\ MagicDisc
[01/19/2009|10:52] C:\Program Files\ Malwarebytes' Anti-Malware
[11/14/2008|07:29] C:\Program Files\ McAfee.com
[09/15/2008|12:47] C:\Program Files\ Messenger
[05/22/2007|01:52] C:\Program Files\ Microsoft ActiveSync
[05/22/2007|12:41] C:\Program Files\ microsoft frontpage
[05/22/2007|01:51] C:\Program Files\ Microsoft Office
[05/22/2007|01:52] C:\Program Files\ Microsoft.NET
[09/15/2008|12:40] C:\Program Files\ Movie Maker
[11/14/2008|07:07] C:\Program Files\ Mozilla Firefox
[05/22/2007|12:34] C:\Program Files\ MSN
[05/22/2007|12:34] C:\Program Files\ MSN Gaming Zone
[11/10/2007|10:33] C:\Program Files\ MSXML 4.0
[08/22/2008|02:42] C:\Program Files\ MySpace
[09/15/2008|12:38] C:\Program Files\ NetMeeting
[05/22/2007|12:36] C:\Program Files\ Online Services
[09/15/2008|12:38] C:\Program Files\ Outlook Express
[11/22/2008|12:03] C:\Program Files\ QuickTime
[01/18/2009|11:23] C:\Program Files\ RegCure
[05/22/2007|01:29] C:\Program Files\ Roxio
[01/19/2009|03:28] C:\Program Files\ Safari
[04/30/2008|11:15] C:\Program Files\ Stardock
[01/19/2009|01:17] C:\Program Files\ Trend Micro
[05/22/2007|12:44] C:\Program Files\ Uninstall Information
[11/04/2008|11:21] C:\Program Files\ Viewpoint
[04/30/2008|10:52] C:\Program Files\ Vista Start Menu
[11/14/2008|07:33] C:\Program Files\ Windows Live
[09/15/2008|02:10] C:\Program Files\ Windows Media Player
[01/18/2009|09:22] C:\Program Files\ Windows NT
[05/22/2007|12:34] C:\Program Files\ WindowsUpdate
[11/14/2008|04:44] C:\Program Files\ WinRAR
[05/22/2007|12:41] C:\Program Files\ xerox
[11/14/2008|04:09] C:\Program Files\ Yahoo!

——————–\\ Listing Folders in C:\Program Files\Common Files

[05/22/2007|01:29] C:\Program Files\Common Files\ Adaptec Shared
[05/07/2008|01:46] C:\Program Files\Common Files\ Adobe
[11/04/2008|11:16] C:\Program Files\Common Files\ AOL
[11/22/2008|12:02] C:\Program Files\Common Files\ Apple
[05/22/2007|01:51] C:\Program Files\Common Files\ DESIGNER
[04/28/2008|03:56] C:\Program Files\Common Files\ INCA Shared
[12/02/2007|12:53] C:\Program Files\Common Files\ InstallShield
[06/12/2007|10:21] C:\Program Files\Common Files\ Java
[11/14/2008|07:33] C:\Program Files\Common Files\ Microsoft Shared
[05/22/2007|12:35] C:\Program Files\Common Files\ MSSoap
[05/22/2007|05:25] C:\Program Files\Common Files\ ODBC
[05/22/2007|12:35] C:\Program Files\Common Files\ Services
[05/22/2007|05:25] C:\Program Files\Common Files\ SpeechEngines
[09/15/2008|12:38] C:\Program Files\Common Files\ System
[11/14/2008|07:40] C:\Program Files\Common Files\ Teleca Shared
[12/13/2007|01:25] C:\Program Files\Common Files\ WindowsLiveInstaller

——————–\\ Process

( 16 Processes )

… OK !

——————–\\ Searching with S_Lop

No Lop folder found !

——————–\\ Searching for Lop Files - Folders

No Lop folder found !

——————–\\ Searching within the Registry

….. OK !

——————–\\ Checking the Hosts file

Hosts file CLEAN


——————–\\ Searching for hidden files with Catchme

catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-01-20 18:28:22
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes …
scanning hidden files …
scan completed successfully
hidden processes: 0
hidden files: 0

——————–\\ Searching for other infections

——————–\\ ROOTKIT !!

Rootkit Tibs ! .. [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_TDSSSERV]
Rootkit Tibs ! .. [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_TDSSSERV]
Rootkit Tibs ! .. [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_TDSSSERV]
Rootkit Tibs ! .. [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\TDSSserv]
Rootkit Tibs ! .. [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\TDSSserv]
Rootkit Tibs ! .. [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\TDSSserv]
Rootkit Tibs ! .. [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\TDSSserv]

——————–\\ Cracks & Keygens ..

C:\DOCUME~1\REDHOO~1\Local Settings\Temp\Temporary Directory 1 for PC_Spore -multi.18- © EA -.direct.play.- ToeD crack keygen.zip
C:\DOCUME~1\REDHOO~1\My Documents\FrostWire\Incomplete\T-380779-The Sims 2 Complete Collection (don_stefan) crack keygen.zip
C:\DOCUME~1\REDHOO~1\My Documents\FrostWire\Incomplete\T-400990-The Sims 2 (Full Version) crack keygen.zip
C:\DOCUME~1\REDHOO~1\My Documents\FrostWire\Incomplete\T-404344-Les Sims 2 Expansion pack 8-en-1 - MULTI - [CUSTOM DVD edition] - DB666 crack keygen.zip
C:\DOCUME~1\REDHOO~1\My Documents\FrostWire\Incomplete\T-446758-The Sims 2 Apartment Life crack keygen.zip
C:\DOCUME~1\REDHOO~1\My Documents\FrostWire\Incomplete\T-6173511-No CD CRACK + keygen - The Sims 2 by XZezin.zip


[F:1558][D:113]-> C:\DOCUME~1\REDHOO~1\LOCALS~1\Temp
[F:1][D:0]-> C:\DOCUME~1\REDHOO~1\Cookies
[F:28][D:8]-> C:\DOCUME~1\REDHOO~1\LOCALS~1\TEMPOR~1\content.IE5

1 - "C:\Lop SD\LopR_1.txt" - Tue 01/20/2009|18:30 - Option : [1]

——————–\\ Scan completed at 18:30:59
OK I can see your problem, cracked programmes and keygens not only give you the programmes illegally they also give you rootkits/Trojans/Spyware/Keyloggers. Congratulations you have them all..

Under the site TOU I must ask you to rmove the pirated software before I can assist . I will help you remove them B)

Please download the OTMoveIt3 by OldTimer.
  • Save it to your desktop.
  • Please double-click OTMoveIt3.exe to run it. (Note: If you are running on Vista, right-click on the file and choose Run As Administrator).
  • Copy the lines in the codebox below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):

    :Files
    C:\DOCUME~1\REDHOO~1\Local Settings\Temp\Temporary Directory 1 for PC_Spore -multi.18- © EA -.direct.play.- ToeD crack keygen.zip
    C:\DOCUME~1\REDHOO~1\My Documents\FrostWire\Incomplete\T-380779-The Sims 2 Complete Collection (don_stefan) crack keygen.zip
    C:\DOCUME~1\REDHOO~1\My Documents\FrostWire\Incomplete\T-400990-The Sims 2 (Full Version) crack keygen.zip
    C:\DOCUME~1\REDHOO~1\My Documents\FrostWire\Incomplete\T-404344-Les Sims 2 Expansion pack 8-en-1 - MULTI - [CUSTOM DVD edition] - DB666 crack keygen.zip
    C:\DOCUME~1\REDHOO~1\My Documents\FrostWire\Incomplete\T-446758-The Sims 2 Apartment Life crack keygen.zip
    C:\DOCUME~1\REDHOO~1\My Documents\FrostWire\Incomplete\T-6173511-No CD CRACK + keygen - The Sims 2 by XZezin.zip
    
    
    :Commands
    [purity]
    [emptytemp]
  • Return to OTMoveIt3, right click in the "Paste Instructions for Items to be Moved" window (under the yellow bar) and choose Paste.
  • Click the red Moveit! button.
  • Copy everything in the Results window (under the green bar) to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it in your next reply.
  • Close OTMoveIt3
Note: If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes. In this case, after the reboot, open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTMoveIt\MovedFiles folder, and open the newest .log file present, and copy/paste the contents of that document back here in your next post.

If you could uninstall the programmes and then post back the OTMoveit log I will continue
i did the OTMoveIt and it moved the files but on reboot it didn't show a log. (probably because i had to restart three times before my computer would boot up all the way) but i did another LopSD scan to show you they were gone.








——————–\\ Lop S&D 4.2.5-0 XP/Vista

Microsoft Windows XP Professional ( v5.1.2600 ) Service Pack 3
X86-based PC ( Uniprocessor Free : Intel® Celeron® CPU 2.40GHz )
BIOS : Phoenix ROM BIOS PLUS Version 1.10 A05
USER : Red Hood ( Administrator )
BOOT : Fail-safe with network boot
C:\ (Local Disk) - NTFS - Total:74 Go (Free:55 Go)
D:\ (CD or DVD)
E:\ (USB)
F:\ (CD or DVD)
G:\ (USB)
H:\ (USB)
I:\ (USB)
J:\ (USB)

"C:\Lop SD" ( MAJ : 19-12-2008|23:40 )
Option : [1] ( Wed 01/21/2009|17:47 )

——————–\\ Listing folders in APPLIC~1

[06/14/2007|11:24] C:\DOCUME~1\ADMINI~1\APPLIC~1\ acccore
[08/13/2007|11:12] C:\DOCUME~1\ADMINI~1\APPLIC~1\ Adobe
[01/18/2009|08:17] C:\DOCUME~1\ADMINI~1\APPLIC~1\ Apple Computer
[06/18/2007|07:03] C:\DOCUME~1\ADMINI~1\APPLIC~1\ CyberLink
[05/25/2007|02:45] C:\DOCUME~1\ADMINI~1\APPLIC~1\ Google
[10/20/2007|01:08] C:\DOCUME~1\ADMINI~1\APPLIC~1\ GTek
[05/22/2007|12:44] C:\DOCUME~1\ADMINI~1\APPLIC~1\ Identities
[05/22/2007|01:23] C:\DOCUME~1\ADMINI~1\APPLIC~1\ Jasc Software Inc
[08/28/2007|02:12] C:\DOCUME~1\ADMINI~1\APPLIC~1\ LimeWire
[05/25/2007|02:03] C:\DOCUME~1\ADMINI~1\APPLIC~1\ Macromedia
[11/15/2007|01:15] C:\DOCUME~1\ADMINI~1\APPLIC~1\ Microsoft
[06/14/2007|11:13] C:\DOCUME~1\ADMINI~1\APPLIC~1\ Mozilla
[11/10/2007|07:08] C:\DOCUME~1\ADMINI~1\APPLIC~1\ Sony Ericsson
[09/22/2007|12:02] C:\DOCUME~1\ADMINI~1\APPLIC~1\ Sun
[12/08/2007|10:49] C:\DOCUME~1\ADMINI~1\APPLIC~1\ Teleca
[06/14/2007|11:30] C:\DOCUME~1\ADMINI~1\APPLIC~1\ Viewpoint

[11/22/2008|12:06] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ {3276BE95_AF08_429F_A64F_CA64CB79BCF6}
[05/07/2008|01:44] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Adobe
[11/04/2008|11:16] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ AOL
[05/08/2008|11:50] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ AOL Downloads
[06/14/2007|11:23] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ AOL OCP
[08/22/2007|10:36] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Apple
[06/14/2007|11:42] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Apple Computer
[05/02/2008|05:55] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ CanonBJ
[05/22/2007|01:22] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ CyberLink
[08/31/2007|03:07] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Google
[10/20/2007|01:06] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ GTek
[01/19/2009|10:52] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Malwarebytes
[11/14/2008|07:29] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ McAfee
[11/14/2008|07:04] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ McAfee.com
[11/14/2008|07:33] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Microsoft
[01/18/2009|11:14] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ TEMP
[11/14/2008|07:09] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Viewpoint
[05/25/2007|09:30] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Windows Genuine Advantage
[12/13/2007|12:45] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ WLInstaller

[10/20/2007|01:08] C:\DOCUME~1\DEFAUL~1\APPLIC~1\ Gtek
[05/22/2007|12:37] C:\DOCUME~1\DEFAUL~1\APPLIC~1\ Microsoft

[12/08/2007|11:06] C:\DOCUME~1\Guest\APPLIC~1\ Gtek
[12/08/2007|11:05] C:\DOCUME~1\Guest\APPLIC~1\ Identities
[12/08/2007|11:05] C:\DOCUME~1\Guest\APPLIC~1\ Microsoft

[05/22/2007|12:44] C:\DOCUME~1\LOCALS~1\APPLIC~1\ Microsoft

[05/22/2007|12:44] C:\DOCUME~1\NETWOR~1\APPLIC~1\ Microsoft

[09/15/2008|11:45] C:\DOCUME~1\REDHOO~1\APPLIC~1\ Adobe
[11/04/2008|11:21] C:\DOCUME~1\REDHOO~1\APPLIC~1\ Aim
[08/07/2008|04:08] C:\DOCUME~1\REDHOO~1\APPLIC~1\ Apple Computer
[06/19/2008|09:44] C:\DOCUME~1\REDHOO~1\APPLIC~1\ Aston
[11/13/2008|05:51] C:\DOCUME~1\REDHOO~1\APPLIC~1\ Canon
[12/09/2007|12:42] C:\DOCUME~1\REDHOO~1\APPLIC~1\ CyberLink
[10/24/2008|12:16] C:\DOCUME~1\REDHOO~1\APPLIC~1\ FrostWire
[12/08/2007|10:30] C:\DOCUME~1\REDHOO~1\APPLIC~1\ Gtek
[12/08/2007|10:30] C:\DOCUME~1\REDHOO~1\APPLIC~1\ Identities
[01/18/2009|07:18] C:\DOCUME~1\REDHOO~1\APPLIC~1\ ijjigame
[08/07/2008|09:54] C:\DOCUME~1\REDHOO~1\APPLIC~1\ LimeWire
[12/19/2008|01:06] C:\DOCUME~1\REDHOO~1\APPLIC~1\ Macromedia
[01/19/2009|10:52] C:\DOCUME~1\REDHOO~1\APPLIC~1\ Malwarebytes
[12/13/2008|12:12] C:\DOCUME~1\REDHOO~1\APPLIC~1\ Microsoft
[01/11/2008|09:27] C:\DOCUME~1\REDHOO~1\APPLIC~1\ MySpace
[01/01/2008|08:49] C:\DOCUME~1\REDHOO~1\APPLIC~1\ SecuROM
[12/08/2007|10:30] C:\DOCUME~1\REDHOO~1\APPLIC~1\ Sony Ericsson
[06/05/2008|11:01] C:\DOCUME~1\REDHOO~1\APPLIC~1\ Sun
[11/14/2008|07:40] C:\DOCUME~1\REDHOO~1\APPLIC~1\ Teleca
[10/24/2008|12:16] C:\DOCUME~1\REDHOO~1\APPLIC~1\ uTorrent

——————–\\ Scheduled Tasks located in C:\WINDOWS\Tasks

[01/19/2009 10:34 AM][–a——] C:\WINDOWS\tasks\RegCure Program Check.job
[01/18/2009 11:12 PM][–a——] C:\WINDOWS\tasks\RegCure.job
[12/12/2008 10:04 PM][–a——] C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[12/16/2008 07:00 AM][–a——] C:\WINDOWS\tasks\McAfee.com Scan for Viruses - My Computer (FAMILY-S6C0SKZX-Administrator).job
[01/19/2009 11:06 AM][–ah—–] C:\WINDOWS\tasks\SA.DAT
[07/16/2003 08:31 AM][-r-h—–] C:\WINDOWS\tasks\desktop.ini

——————–\\ Listing Folders in C:\Program Files

[12/01/2007|01:15] C:\Program Files\ Acoustica MP3 To Wave Converter PLUS
[08/22/2008|02:39] C:\Program Files\ Adobe
[11/04/2008|11:21] C:\Program Files\ AIM
[11/04/2008|11:21] C:\Program Files\ AOD
[08/06/2008|03:46] C:\Program Files\ Apple Software Update
[12/02/2007|12:11] C:\Program Files\ Atari
[08/22/2008|02:41] C:\Program Files\ Audio Converter
[10/13/2008|01:26] C:\Program Files\ Bonjour
[05/22/2007|01:09] C:\Program Files\ Broadcom
[05/22/2007|01:16] C:\Program Files\ Broadcom Management Programs
[05/02/2008|05:50] C:\Program Files\ Canon
[01/19/2009|11:05] C:\Program Files\ Common Files
[05/22/2007|12:34] C:\Program Files\ ComPlus Applications
[05/22/2007|01:30] C:\Program Files\ CyberLink
[05/22/2007|01:22] C:\Program Files\ Dell
[11/24/2007|05:15] C:\Program Files\ DivX
[10/13/2008|12:15] C:\Program Files\ Electronic Arts
[09/01/2007|12:44] C:\Program Files\ Empire Interactive
[08/31/2007|03:14] C:\Program Files\ FirstClass
[10/13/2008|01:02] C:\Program Files\ FrostWire
[09/06/2007|02:50] C:\Program Files\ Google
[01/19/2009|01:09] C:\Program Files\ Hijackthis
[11/14/2008|07:57] C:\Program Files\ InstallShield Installation Information
[05/22/2007|12:58] C:\Program Files\ Intel
[12/13/2008|12:06] C:\Program Files\ Internet Explorer
[11/22/2008|12:06] C:\Program Files\ iPod
[11/22/2008|12:06] C:\Program Files\ iTunes
[10/13/2008|12:14] C:\Program Files\ Jasc Software Inc
[12/18/2008|02:27] C:\Program Files\ Java
[10/13/2008|12:14] C:\Program Files\ LimeWire
[10/20/2007|01:08] C:\Program Files\ Linksys EasyLink Advisor
[10/23/2008|11:58] C:\Program Files\ MagicDisc
[01/19/2009|10:52] C:\Program Files\ Malwarebytes' Anti-Malware
[11/14/2008|07:29] C:\Program Files\ McAfee.com
[09/15/2008|12:47] C:\Program Files\ Messenger
[05/22/2007|01:52] C:\Program Files\ Microsoft ActiveSync
[05/22/2007|12:41] C:\Program Files\ microsoft frontpage
[05/22/2007|01:51] C:\Program Files\ Microsoft Office
[05/22/2007|01:52] C:\Program Files\ Microsoft.NET
[09/15/2008|12:40] C:\Program Files\ Movie Maker
[11/14/2008|07:07] C:\Program Files\ Mozilla Firefox
[05/22/2007|12:34] C:\Program Files\ MSN
[05/22/2007|12:34] C:\Program Files\ MSN Gaming Zone
[11/10/2007|10:33] C:\Program Files\ MSXML 4.0
[08/22/2008|02:42] C:\Program Files\ MySpace
[09/15/2008|12:38] C:\Program Files\ NetMeeting
[05/22/2007|12:36] C:\Program Files\ Online Services
[09/15/2008|12:38] C:\Program Files\ Outlook Express
[11/22/2008|12:03] C:\Program Files\ QuickTime
[01/18/2009|11:23] C:\Program Files\ RegCure
[05/22/2007|01:29] C:\Program Files\ Roxio
[01/19/2009|03:28] C:\Program Files\ Safari
[04/30/2008|11:15] C:\Program Files\ Stardock
[01/19/2009|01:17] C:\Program Files\ Trend Micro
[05/22/2007|12:44] C:\Program Files\ Uninstall Information
[11/04/2008|11:21] C:\Program Files\ Viewpoint
[04/30/2008|10:52] C:\Program Files\ Vista Start Menu
[11/14/2008|07:33] C:\Program Files\ Windows Live
[09/15/2008|02:10] C:\Program Files\ Windows Media Player
[01/18/2009|09:22] C:\Program Files\ Windows NT
[05/22/2007|12:34] C:\Program Files\ WindowsUpdate
[11/14/2008|04:44] C:\Program Files\ WinRAR
[05/22/2007|12:41] C:\Program Files\ xerox
[11/14/2008|04:09] C:\Program Files\ Yahoo!

——————–\\ Listing Folders in C:\Program Files\Common Files

[05/22/2007|01:29] C:\Program Files\Common Files\ Adaptec Shared
[05/07/2008|01:46] C:\Program Files\Common Files\ Adobe
[11/04/2008|11:16] C:\Program Files\Common Files\ AOL
[11/22/2008|12:02] C:\Program Files\Common Files\ Apple
[05/22/2007|01:51] C:\Program Files\Common Files\ DESIGNER
[04/28/2008|03:56] C:\Program Files\Common Files\ INCA Shared
[12/02/2007|12:53] C:\Program Files\Common Files\ InstallShield
[06/12/2007|10:21] C:\Program Files\Common Files\ Java
[11/14/2008|07:33] C:\Program Files\Common Files\ Microsoft Shared
[05/22/2007|12:35] C:\Program Files\Common Files\ MSSoap
[05/22/2007|05:25] C:\Program Files\Common Files\ ODBC
[05/22/2007|12:35] C:\Program Files\Common Files\ Services
[05/22/2007|05:25] C:\Program Files\Common Files\ SpeechEngines
[09/15/2008|12:38] C:\Program Files\Common Files\ System
[11/14/2008|07:40] C:\Program Files\Common Files\ Teleca Shared
[12/13/2007|01:25] C:\Program Files\Common Files\ WindowsLiveInstaller

——————–\\ Process

( 16 Processes )

… OK !

——————–\\ Searching with S_Lop

No Lop folder found !

——————–\\ Searching for Lop Files - Folders

No Lop folder found !

——————–\\ Searching within the Registry

….. OK !

——————–\\ Checking the Hosts file

Hosts file CLEAN


——————–\\ Searching for hidden files with Catchme

catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-01-21 17:49:23
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes …
scanning hidden files …
scan completed successfully
hidden processes: 0
hidden files: 0

——————–\\ Searching for other infections

——————–\\ ROOTKIT !!

Rootkit Tibs ! .. [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_TDSSSERV]
Rootkit Tibs ! .. [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_TDSSSERV]
Rootkit Tibs ! .. [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_TDSSSERV]
Rootkit Tibs ! .. [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\TDSSserv]
Rootkit Tibs ! .. [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\TDSSserv]
Rootkit Tibs ! .. [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\TDSSserv]
Rootkit Tibs ! .. [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\TDSSserv]



[F:1][D:1]-> C:\DOCUME~1\REDHOO~1\LOCALS~1\Temp
[F:1][D:0]-> C:\DOCUME~1\REDHOO~1\Cookies
[F:24][D:8]-> C:\DOCUME~1\REDHOO~1\LOCALS~1\TEMPOR~1\content.IE5

1 - "C:\Lop SD\LopR_1.txt" - Tue 01/20/2009|18:30 - Option : [1]
2 - "C:\Lop SD\LopR_2.txt" - Wed 01/21/2009|17:51 - Option : [1]

——————–\\ Scan completed at 17:51:48
Excellent to continue

Download Combofix from any of the links below. You must rename it before saving it. Save it to your desktop.

Link 1
Link 2
Link 3

[external image: Posted Image]


[external image: Posted Image]
——————————————————————–

Double click on Combo-Fix.exe & follow the prompts.
  • When finished, it will produce a report for you.
  • Please post the C:\ComboFix.txt along with a HijackThis log so we can continue cleaning the system.
combofix log



ComboFix 09-01-21.04 - Red Hood 2009-01-22 19:59:12.1 - NTFSx86 NETWORK
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.510.289 [GMT -8:00]
Running from: c:\documents and settings\[removed]\Desktop\Combo-Fix.exe
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\Red Hood\Local Settings\Temporary Internet Files\ijjistarter_verinfo.dat
c:\windows\system32\drivers\fad.sys
c:\windows\system32\msssc.dll

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Legacy_TDSSSERV
——-\Service_TDSSserv


((((((((((((((((((((((((( Files Created from 2008-12-23 to 2009-01-23 )))))))))))))))))))))))))))))))
.

2009-01-21 16:33 . 2009-01-21 16:33 d——– C:\_OTMoveIt
2009-01-20 18:17 . 2009-01-21 17:51 d——– C:\Lop SD
2009-01-19 13:17 . 2009-01-19 13:17 d——– c:\program files\Trend Micro
2009-01-19 10:52 . 2009-01-19 10:52 d——– c:\program files\Malwarebytes' Anti-Malware
2009-01-19 10:52 . 2009-01-19 10:52 d——– c:\documents and settings\Red Hood\Application Data\Malwarebytes
2009-01-19 10:52 . 2009-01-19 10:52 d——– c:\documents and settings\All Users\Application Data\Malwarebytes
2009-01-19 10:52 . 2009-01-14 16:11 38,496 –a—— c:\windows\system32\drivers\mbamswissarmy.sys
2009-01-19 10:52 . 2009-01-14 16:11 15,504 –a—— c:\windows\system32\drivers\mbam.sys
2009-01-18 20:25 . 2009-01-18 20:25 d——– c:\windows\RegCure
2009-01-18 20:25 . 2009-01-18 23:23 d——– c:\program files\RegCure

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-01-23 04:07 69,632 —-a-w c:\windows\system32\drivers\irfpmb6riss.sys
2009-01-19 23:28 ——— d—–w c:\program files\Safari
2009-01-19 07:54 90,112 —-a-w c:\windows\DUMP4a57.tmp
2009-01-19 07:51 90,112 —-a-w c:\windows\DUMP6a33.tmp
2009-01-19 07:14 ——— d—a-w c:\documents and settings\All Users\Application Data\TEMP
2009-01-19 04:17 ——— d—–w c:\documents and settings\Administrator\Application Data\Apple Computer
2009-01-19 03:18 ——— d–h–w c:\documents and settings\Red Hood\Application Data\ijjigame
2008-12-18 22:27 ——— d—–w c:\program files\Java
2008-06-20 05:44 0 -c–a-w c:\program files\AstonWriteTest.txt
2008-06-19 08:09 445,440 –sh–w c:\program files\Common Files\msdp.dll
2008-10-14 20:17 32,768 -csha-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012008101420081015\index.dat
2008-10-17 19:01 32,768 -csha-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012008101720081018\index.dat
2008-10-19 11:44 32,768 -csha-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012008101920081020\index.dat
2008-10-22 22:17 32,768 -csha-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012008102220081023\index.dat
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"EasyLinkAdvisor"="c:\program files\Linksys EasyLink Advisor\LinksysAgent.exe" [2007-03-15 454784]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-13 15360]
"AIM"="c:\progra~1\AIM\aim.exe" [2006-08-01 67112]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-11-20 290088]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2005-06-21 155648]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2005-06-21 126976]
"PCMService"="c:\program files\Dell\Media Experience\PCMService.exe" [2004-04-11 290816]
"AdaptecDirectCD"="c:\program files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe" [2002-10-02 684032]
"DVDLauncher"="c:\program files\CyberLink\PowerDVD\DVDLauncher.exe" [2004-10-12 57344]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2008-12-18 136600]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-11-04 413696]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"GrpConv"="grpconv -o" [X]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\irfpmb6riss.sys]
@="\??\c:\windows\system32\drivers\irfpmb6riss.sys"
path=
backup=

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"AntiVirusOverride"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\FrostWire\\FrostWire.exe"=
"c:\\Program Files\\AIM\\aim.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=

S4 irfpmb6riss.sys;irfpmb6riss.sys;c:\windows\system32\drivers\irfpmb6riss.sys [2003-07-16 69632]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{38d2ffec-a6e1-11dd-b566-000f1f51d239}]
\Shell\AutoRun\command - E:\xk2n.bat
\Shell\explore\Command - E:\xk2n.bat
\Shell\open\Command - E:\xk2n.bat
.
Contents of the 'Scheduled Tasks' folder

2008-12-13 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 10:34]

2008-12-16 c:\windows\Tasks\McAfee.com Scan for Viruses - My Computer (FAMILY-S6C0SKZX-Administrator).job
- c:\program files\mcafee.com\vso\mcmnhdlr.exe []

2009-01-19 c:\windows\Tasks\RegCure Program Check.job
- c:\program files\RegCure\RegCure.exe [2007-08-02 00:20]

2009-01-19 c:\windows\Tasks\RegCure.job
- c:\program files\RegCure\RegCure.exe [2007-08-02 00:20]
.
- - - - ORPHANS REMOVED - - - -

HKLM-RunOnce- - (no file)
MSConfigStartUp-VirusHeal 4 - c:\program files\VirusHeal 4.0\VirusHeal 4.0.exe


.
——- Supplementary Scan ——-
.
uInternet Connection Wizard,ShellNext = https://login.live.com/resetpw.srf?lc=1033
uInternet Settings,ProxyOverride = *.local
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: Easy-WebPrint Add To Print List - c:\program files\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html
IE: Easy-WebPrint High Speed Print - c:\program files\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html
IE: Easy-WebPrint Preview - c:\program files\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html
IE: Easy-WebPrint Print - c:\program files\Canon\Easy-WebPrint\Resource.dll/RC_Print.html
DPF: {036F8A56-0BC8-4607-8F98-D3231E6FF5ED} - hxxp://centra01.ccsd.net/SiteRoots/main/Install/win32/CentraUpdaterAx.cab
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-01-22 22:51:39
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2009-01-22 22:56:05 - machine was rebooted
ComboFix-quarantined-files.txt 2009-01-23 06:55:59

Pre-Run: 59,751,047,168 bytes free
Post-Run: 60,478,767,104 bytes free

WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /fastdetect /NoExecute=OptIn

133








andddd hijack this log

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:56:33 PM, on 1/22/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16762)
Boot mode: Safe mode with network support

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = https://login.live.com/resetpw.srf?lc=1033
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)
O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\RunOnce: [GrpConv] grpconv -o
O4 - HKCU\..\Run: [EasyLinkAdvisor] "C:\Program Files\Linksys EasyLink Advisor\LinksysAgent.exe" /startup
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [AIM] C:\PROGRA~1\AIM\aim.exe -cnetwait.odl
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Easy-WebPrint Add To Print List - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html
O8 - Extra context menu item: Easy-WebPrint High Speed Print - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html
O8 - Extra context menu item: Easy-WebPrint Preview - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html
O8 - Extra context menu item: Easy-WebPrint Print - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Print.html
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\PROGRA~1\AIM\aim.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {036F8A56-0BC8-4607-8F98-D3231E6FF5ED} - http://centra01.ccsd.net/SiteRoots/main/In…raUpdaterAx.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1180113720703
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} - http://download.divx.com/player/DivXBrowserPlugin.cab
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe

–
End of file - 5328 bytes
OK this time I would like you to run the following in normal mode. What antivirus are you using as I can see no evidence of one on this log ?

1. Please open Notepad
  • Click Start , then Run
  • Type notepad .exe in the Run Box.

2. Now copy/paste the entire content of the codebox below into the Notepad window:

File::
c:\program files\Common Files\msdp.dll

Registry::
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{38d2ffec-a6e1-11dd-b566-000f1f51d239}]

3. Then in the text file go to FILE > SAVE AS and in the dropdown box select SAVE AS TYPE to ALL FILES

4. Save the above as CFScript.txt

5. Then drag the CFScript.txt into ComboFix.exe as depicted in the animation below. This will start ComboFix again.

[external image: Posted Image]


6. After reboot, (in case it asks to reboot), please post the following reports/logs into your next reply:
  • Combofix.txt
  • A new HijackThis log.

Also do you use your USB drive a lot ? If so I would like you to download and run the following programme

  • 1 - Flash Drive Disinfector
    Download Flash_Disinfector.exe by sUBs from >here< and save it to your desktop.
  • Double-click Flash_Disinfector.exe to run it and follow any prompts that may appear.
  • The utility may ask you to insert your flash drive and/or other removable drives including your mobile phone. Please do so and allow the utility to clean up those drives as well.
  • Wait until it has finished scanning and then exit the program.
  • Reboot your computer when done.
Note: Flash_Disinfector will create a hidden folder named autorun.inf in each partition and every USB drive plugged in when you ran it. Don't delete this folder…it will help protect your drives from future infection.

Logs required : Combofix and an update on how your system is performing
I booted up in normal mode fine but before i could get to the forum the window popped up "safari has encountered a problem and must close" i tried opening it again and the same thing happened, so I tried opening Internet Explorer but the moment I did that the entire computer froze, mouse, keyboard everything, and I don't have any other browsers downloaded. So I manually shut it down and started it back up in safe mode. Is it okay for me to run the combofix in safe mode? And I currently don't have an anti-virus… I PAID for Virus Heal so that was it… until i found out it's not an anti-virus. But when we're done I would like some recommendations please.
OK I will give you the download an instalation instructions for an antivirus, I am using this one as it has a bootscan facility you can change it afterwards if you do not like it. I would like to get it installed before we proceed any further

Please go HERE and download avast! 4 Home Edition to your desktop. Locate the file that you just downloaded, double-click on the file to launch the installation of avast!

Click Next on the avast! Setup window and on the next window with the ReadMe File.
Now you will see the Legal Agreement, just click I agree, and then click Next to continue.

You will be prompted with Configuration window, make sure that you choose Typical configuration and then click Next. Click Next to the windows that will follow, when the installation will finish, you will be given an option to schedule a boot time scan, select No

Now you have to restart your machine, select Restart and then click Finish.

After you restart you will get a message about avast! it will give you the general "Hello and Thank you for choosing our Product." Also after you restart you will notice 2 new icons in the bottom right corner of the screen.

VERY IMPORTANT - after restarting, right click on the @ in the taskbar and select Updating, then highlight and click Program.

You will get popup after its done updating. If avast! had to download anything for your computer you may get a message asking you to restart.

After you have updated avast! right click the small icon a in task bar and click Start Avast! AntiVirus

Click Program Registration and you will be taken to their website. Fill out the form and then check you e-mail. Once you get an e-mail from them (usually about 1 minute after submitting the form) copy and paste the serial they provided into the highlighted box. Then click ok.

After this, you will need to Schedule Boot-Time Scan with avast! Click on the little button placed up in the left corner, and select Schedule Boot-Time Scan. Read also this tutorial HERE it may make it easier to you to follow the steps.

Next, choose
  • Scan all local disks
  • scan archive files
  • click on Schedule
On the next dialog Operating system restart needed select Yes
Now avast! will restart your computer and start to scan before Windows fully loads.

IMPORTANT NOTE since your system has infections on it, avast! will give you dialog box with recommended actions, and options, please make sure if this happens, to click the Move to Chest button, and not to delete any reported files.

The boot log will be located here C:\Program Files\Alwil Software\Avast4\DATA\report\AswBoot.txt
here is the scan log. i am also able to boot up in normal mode and us safari without any problems, just the booting up is somewhat slow. 01/25/2009 16:09 Scan of all local drives File C:\Program Files\Common Files\msdp.dll is infected by Win32:Trojan-gen {Other}, Moved to chest File C:\System Volume Information\_restore{ED09BE80-0EF3-4F81-B316-EF0E7586D2A7}\RP618\A0041598.sys is infected by Win32:Rootkit-gen [Rtk], Moved to chest File C:\System Volume Information\_restore{ED09BE80-0EF3-4F81-B316-EF0E7586D2A7}\RP618\A0041603.dll is infected by Win32:TdCrypt [Cryp], Moved to chest File C:\System Volume Information\_restore{ED09BE80-0EF3-4F81-B316-EF0E7586D2A7}\RP618\A0042599.sys is infected by Win32:Rootkit-gen [Rtk], Moved to chest File C:\System Volume Information\_restore{ED09BE80-0EF3-4F81-B316-EF0E7586D2A7}\RP618\A0043597.sys is infected by Win32:Rootkit-gen [Rtk], Moved to chest File C:\System Volume Information\_restore{ED09BE80-0EF3-4F81-B316-EF0E7586D2A7}\RP618\A0043608.sys is infected by Win32:Rootkit-gen [Rtk], Moved to chest File C:\System Volume Information\_restore{ED09BE80-0EF3-4F81-B316-EF0E7586D2A7}\RP618\A0043616.sys is infected by Win32:Rootkit-gen [Rtk], Moved to chest File C:\System Volume Information\_restore{ED09BE80-0EF3-4F81-B316-EF0E7586D2A7}\RP618\A0044616.sys is infected by Win32:Rootkit-gen [Rtk], Moved to chest File C:\System Volume Information\_restore{ED09BE80-0EF3-4F81-B316-EF0E7586D2A7}\RP620\A0046621.sys is infected by Win32:Rootkit-gen [Rtk], Moved to chest File C:\System Volume Information\_restore{ED09BE80-0EF3-4F81-B316-EF0E7586D2A7}\RP621\A0049619.sys is infected by Win32:Rootkit-gen [Rtk], Moved to chest File C:\System Volume Information\_restore{ED09BE80-0EF3-4F81-B316-EF0E7586D2A7}\RP621\A0049623.sys is infected by Win32:Rootkit-gen [Rtk], Moved to chest File C:\System Volume Information\_restore{ED09BE80-0EF3-4F81-B316-EF0E7586D2A7}\RP621\A0049633.sys is infected by Win32:Rootkit-gen [Rtk], Moved to chest File C:\System Volume Information\_restore{ED09BE80-0EF3-4F81-B316-EF0E7586D2A7}\RP623\A0050633.sys is infected by Win32:Rootkit-gen [Rtk], Moved to chest File C:\System Volume Information\_restore{ED09BE80-0EF3-4F81-B316-EF0E7586D2A7}\RP623\A0050765.sys is infected by Win32:Rootkit-gen [Rtk], Moved to chest File C:\System Volume Information\_restore{ED09BE80-0EF3-4F81-B316-EF0E7586D2A7}\RP624\A0052764.sys is infected by Win32:Rootkit-gen [Rtk], Moved to chest File C:\System Volume Information\_restore{ED09BE80-0EF3-4F81-B316-EF0E7586D2A7}\RP624\A0052774.exe is infected by Win32:FakeAV-L [Trj], Moved to chest File C:\System Volume Information\_restore{ED09BE80-0EF3-4F81-B316-EF0E7586D2A7}\RP624\A0052777.exe is infected by Win32:Spycrush [Tool], Moved to chest File C:\System Volume Information\_restore{ED09BE80-0EF3-4F81-B316-EF0E7586D2A7}\RP624\A0052780.exe is infected by Win32:Zlob-BTE [Trj], Moved to chest File C:\System Volume Information\_restore{ED09BE80-0EF3-4F81-B316-EF0E7586D2A7}\RP624\A0052813.sys is infected by Win32:Rootkit-gen [Rtk], Moved to chest File C:\System Volume Information\_restore{ED09BE80-0EF3-4F81-B316-EF0E7586D2A7}\RP624\A0053876.sys is infected by Win32:Rootkit-gen [Rtk], Moved to chest File C:\System Volume Information\_restore{ED09BE80-0EF3-4F81-B316-EF0E7586D2A7}\RP625\A0054877.sys is infected by Win32:Rootkit-gen [Rtk], Moved to chest File C:\System Volume Information\_restore{ED09BE80-0EF3-4F81-B316-EF0E7586D2A7}\RP625\A0055884.sys is infected by Win32:Rootkit-gen [Rtk], Moved to chest File C:\System Volume Information\_restore{ED09BE80-0EF3-4F81-B316-EF0E7586D2A7}\RP625\A0055890.dll is infected by Win32:Trojan-gen {Other}, Moved to chest File C:\window blinds\WindowBlinds602_enhanced.exe\[ASPack] is infected by Win32:Binder-AI [Trj], Moved to chest File C:\WINDOWS\system32\drivers\irfpmb6riss.sys is infected by Win32:Rootkit-gen [Rtk], Moved to chest Number of searched folders: 7303 Number of tested files: 64673 Number of infected files: 25
OK it looks like Avast found most of the Nasties in system restore - we will clear that later.

So I will now run a sweep for orphans, see what that reveals and then look at a spring clean

Please download Malwarebytes' Anti-Malware from Here or Here

Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.
Extra Note:
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediatly.

Logs required : MBAM and a new Hijackthis log
Malwarebytes' Anti-Malware 1.33
Database version: 1697
Windows 5.1.2600 Service Pack 3

1/26/2009 2:59:21 PM
mbam-log-2009-01-26 (14-59-21).txt

Scan type: Quick Scan
Objects scanned: 54637
Time elapsed: 5 minute(s), 21 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)











Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 2:50:30 PM, on 1/26/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16762)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\Dell\Media Experience\PCMService.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Linksys EasyLink Advisor\LinksysAgent.exe
C:\WINDOWS\system32\ctfmon.exe
C:\PROGRA~1\AIM\aim.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = https://login.live.com/resetpw.srf?lc=1033
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)
O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKCU\..\Run: [EasyLinkAdvisor] "C:\Program Files\Linksys EasyLink Advisor\LinksysAgent.exe" /startup
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [AIM] C:\PROGRA~1\AIM\aim.exe -cnetwait.odl
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Easy-WebPrint Add To Print List - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html
O8 - Extra context menu item: Easy-WebPrint High Speed Print - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html
O8 - Extra context menu item: Easy-WebPrint Preview - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html
O8 - Extra context menu item: Easy-WebPrint Print - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Print.html
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\PROGRA~1\AIM\aim.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {036F8A56-0BC8-4607-8F98-D3231E6FF5ED} - http://centra01.ccsd.net/SiteRoots/main/In…raUpdaterAx.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1180113720703
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} - http://download.divx.com/player/DivXBrowserPlugin.cab
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe

–
End of file - 6834 bytes

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI