I was advised by cryptodan to post my logs here.
Link to my other topic at "Am I Infected, What do I do?", http://www.bleepingcomputer.com/forums/topic398710.html
Basically I ran a MBAM scan and removed a few things. Upon restart, I noticed all my desktop icons, folders on my second hard drive, and start menu (like Programs) were missing. I read around the forums and found the useful tool unhide.exe. I ran that and all my icons came back. One question though, all the shortcuts in the start menu like for example, Start Menu>Programs>Games>Call of Duty, is missing. Do I have to recreate those?
I just want to make sure there are no left-overs.
Thanks.
.
DDS (Ver_11-05-19.01) - NTFSx86
Internet Explorer: 7.0.5730.13 BrowserJavaVersion: 1.6.0_23
Run by Administrator at 8:08:35 on 2011-05-25
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2046.1281 [GMT -4:00]
.
AV: avast! Antivirus *Enabled/Updated* {7591DB91-41F0-48A3-B128-1A293FD8233D}
.
============== Running Processes ===============
.
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\Program Files\Accessories\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
C:\Program Files\Avast5\AvastSvc.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\Avast5\avastUI.exe
C:\Program Files\HP\ToolboxFX\bin\HPTLBXFX.exe
C:\WINDOWS\vVX3000.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\inetsrv\inetinfo.exe
C:\WINDOWS\system32\oodag.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\tcpsvcs.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files\HP\HPLaserJetService\HPLaserJetService.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\PnkBstrB.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\Documents and Settings\Administrator\Desktop\dds.scr
C:\WINDOWS\system32\WSCRIPT.exe
.
============== Pseudo HJT Report ===============
.
uInternet Settings,ProxyOverride = <local>;*.local
TB: Adobe PDF: {47833539-d0c5-4125-9fa8-0819e2eaac93} - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll
TB: {A057A204-BACC-4D26-8398-26FADCF27386} - No File
mRun: [avast5] c:\progra~1\avast5\avastUI.exe /nogui
mRun: [ToolboxFX] "c:\program files\hp\toolboxfx\bin\HPTLBXFX.exe" /enum:on /alerts:on /notifications:on /fl:on /fr:on /appData:on /tmcp:on
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [VX3000] c:\windows\vVX3000.exe
uPolicies-explorer: NoRecentDocsNetHood = 01000000
uPolicies-explorer: NoSMMyPictures = 01000000
uPolicies-explorer: NoSMHelp = 01000000
Trusted Zone: intuit.com\ttlc
DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://download.microsoft.com/download/5/b/0/5b0d4654-aa20-495c-b89f-c1c34c691085/LegitCheckControl.cab
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1264357330796
DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1262807130484
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SEH: Microsoft AntiMalware ShellExecuteHook: {091eb208-39dd-417d-a5dd-7e2c2d8fb9cb} - c:\progra~1\access~1\window~1\MpShHook.dll
SecurityProviders: msapsspc.dll, schannel.dll, digest.dll, credssp.dll, msnsspc.dll
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\documents and settings\administrator\application data\mozilla\firefox\profiles\hu3p0pw2.default\
FF - prefs.js: browser.startup.homepage - hxxp://sports.yahoo.com/fantasy
FF - prefs.js: network.proxy.type - 0
FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\microsoft silverlight\4.0.60310.0\npctrlui.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npatgpc.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npdeployJava1.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npdnu.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npdnupdater2.dll
.
---- FIREFOX POLICIES ----
FF - user.js: network.protocol-handler.warn-external.dnupdate - false
============= SERVICES / DRIVERS ===============
.
R1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys [2011-5-20 441176]
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [2010-6-15 307928]
R1 SASDIFSV;SASDIFSV;c:\program files\accessories\superantispyware\sasdifsv.sys [2008-8-20 8944]
R1 SASKUTIL;SASKUTIL;c:\program files\accessories\superantispyware\SASKUTIL.SYS [2008-8-20 55024]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2010-6-15 19544]
R2 avast! Antivirus;avast! Antivirus;c:\program files\avast5\AvastSvc.exe [2010-6-15 42184]
R2 HP LaserJet Service;HP LaserJet Service;c:\program files\hp\hplaserjetservice\HPLaserJetService.exe [2010-4-12 142336]
R2 WinDefend;Windows Defender;c:\program files\accessories\windows defender\MsMpEng.exe [2006-11-3 13592]
S3 HPFXBULKLEDM;HPFXBULKLEDM;c:\windows\system32\drivers\hppcbulkio.sys [2011-4-8 20504]
S3 HPFXFAX;HPFXFAX;c:\windows\system32\drivers\hppcfaxio.sys [2011-4-8 21528]
S3 SASENUM;SASENUM;c:\program files\accessories\superantispyware\SASENUM.SYS [2008-8-20 7408]
.
=============== File Associations ===============
.
chm.file="hh.exe" %1
txtfile=c:\windows\notepad.exe %1
.
=============== Created Last 30 ================
.
2011-05-22 19:56:14 89048 ----a-w- c:\program files\mozilla firefox\libEGL.dll
2011-05-22 19:56:14 781272 ----a-w- c:\program files\mozilla firefox\mozsqlite3.dll
2011-05-22 19:56:14 465880 ----a-w- c:\program files\mozilla firefox\libGLESv2.dll
2011-05-22 19:56:14 1974616 ----a-w- c:\program files\mozilla firefox\D3DCompiler_42.dll
2011-05-22 19:56:14 1892184 ----a-w- c:\program files\mozilla firefox\d3dx9_42.dll
2011-05-22 19:56:14 1874904 ----a-w- c:\program files\mozilla firefox\mozjs.dll
2011-05-22 19:56:14 15832 ----a-w- c:\program files\mozilla firefox\mozalloc.dll
2011-05-22 19:56:14 142296 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
2011-05-21 03:12:05 441176 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2011-05-14 21:44:17 675088 ----a-w- C:\RealPlayer.exe
.
==================== Find3M ====================
.
2011-05-25 02:56:10 138376 ----a-w- c:\windows\system32\drivers\PnkBstrK.sys
2011-05-25 02:55:48 202448 ----a-w- c:\windows\system32\PnkBstrB.exe
2011-05-25 02:55:48 202448 ----a-w- c:\windows\system32\PnkBstrB.ex0
2011-05-10 12:10:59 40112 ----a-w- c:\windows\avastSS.scr
2011-04-08 16:53:12 608 --sha-w- c:\windows\system32\winzvprt5.sys
2011-04-08 11:28:58 41872 ----a-w- c:\windows\system32\xfcodec.dll
2011-04-06 15:16:33 240592 ----a-w- c:\windows\system32\nvdrsdb0.bin
2011-04-06 15:16:33 1 ----a-w- c:\windows\system32\nvdrssel.bin
2011-04-06 15:16:30 240592 ----a-w- c:\windows\system32\nvdrsdb1.bin
2011-04-01 00:44:57 271200 ----a-w- c:\windows\system32\PnkBstrB.xtr
2011-03-18 00:50:52 1068544 ----a-w- C:\CouponPrinter.exe
.
============= FINISH: 8:09:43.68 ===============


Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.
This topic is locked

Back to top



















