Hi,
I've been getting Google redirects to different websites (such as infomash) since yesterday. My computer is running XP Professional, and I ran Malwarebytes yesterday and didn't find anything. This morning a fake scanner (Live Security Platinum) started running, so I shutdown the computer, rebooted and then ran Malwarebyte again. This time it found 9 infected files and removed them. Malwarebytes now shows it's clean again, but I'm still getting redirects.
This afternoon I ran SecurityCheck, but it didn't create a log file and diplayed an error that said "The procedure entry point MigrateWinsockConfiguration could not be located in the dynamic link library MSWSOCK.dll".
I also ran Farbar Service Scanner, MiniToolBox, and aswMBR. The logs for these are shown below.
Can you please help me?
Thanks!
__________________________________________________________________
Farbar Service Scanner Version: 19-06-2012 01
Ran by Shawn (administrator) on 19-06-2012 at 16:47:18
Running from "C:\Documents and Settings\Shawn\Desktop"
Microsoft Windows XP Professional Service Pack 3 (X86)
Boot Mode: Normal
****************************************************************
Internet Services:
============
Connection Status:
==============
Localhost is accessible.
LAN connected.
Google IP is accessible.
Google.com is accessible.
Yahoo IP is accessible.
Yahoo.com is accessible.
Windows Firewall:
=============
Firewall Disabled Policy:
==================
System Restore:
============
System Restore Disabled Policy:
========================
Security Center:
============
wscsvc Service is not running. Checking service configuration:
Checking Start type: ATTENTION!=====> Unable to open wscsvc registry key. The service key does not exist.
Checking ImagePath: ATTENTION!=====> Unable to open wscsvc registry key. The service key does not exist.
Checking ServiceDll: ATTENTION!=====> Unable to open wscsvc registry key. The service key does not exist.
Windows Update:
============
Windows Autoupdate Disabled Policy:
============================
File Check:
========
C:\WINDOWS\system32\dhcpcsvc.dll => MD5 is legit
C:\WINDOWS\system32\Drivers\afd.sys => MD5 is legit
C:\WINDOWS\system32\Drivers\netbt.sys => MD5 is legit
C:\WINDOWS\system32\Drivers\tcpip.sys => MD5 is legit
C:\WINDOWS\system32\Drivers\ipsec.sys => MD5 is legit
C:\WINDOWS\system32\dnsrslvr.dll => MD5 is legit
C:\WINDOWS\system32\ipnathlp.dll => MD5 is legit
C:\WINDOWS\system32\netman.dll => MD5 is legit
C:\WINDOWS\system32\wbem\WMIsvc.dll => MD5 is legit
C:\WINDOWS\system32\srsvc.dll => MD5 is legit
C:\WINDOWS\system32\Drivers\sr.sys => MD5 is legit
C:\WINDOWS\system32\wscsvc.dll => MD5 is legit
C:\WINDOWS\system32\wbem\WMIsvc.dll => MD5 is legit
C:\WINDOWS\system32\wuauserv.dll => MD5 is legit
C:\WINDOWS\system32\qmgr.dll => MD5 is legit
C:\WINDOWS\system32\es.dll => MD5 is legit
C:\WINDOWS\system32\cryptsvc.dll => MD5 is legit
C:\WINDOWS\system32\svchost.exe => MD5 is legit
C:\WINDOWS\system32\rpcss.dll => MD5 is legit
C:\WINDOWS\system32\services.exe => MD5 is legit
**** End of log ****
__________________________________________________________________
MiniToolBox by Farbar Version: 09-06-2012
Ran by Shawn (administrator) on 19-06-2012 at 16:51:17
Microsoft Windows XP Professional Service Pack 3 (X86)
Boot Mode: Normal
***************************************************************************
========================= IE Proxy Settings: ==============================
Proxy is not enabled.
No Proxy Server is set.
========================= FF Proxy Settings: ==============================
========================= Hosts content: =================================
127.0.0.1 localhost
========================= IP Configuration: ================================
Intel® 82567LM Gigabit Network Connection = Local Area Connection 2 (Connected)
1394 Net Adapter = 1394 Connection (Connected)
Ericsson F3507g Mobile Broadband Minicard Network Adapter = Local Area Connection (Media disconnected)
11b/g Wireless LAN Mini PCI Express Adapter III = Wireless Network Connection (Media disconnected)
The following helper DLL cannot be loaded: IFMON.DLL.
The following command was not found: int ip dump.
Windows IP Configuration
Host Name . . . . . . . . . . . . : LENOVO-641B743A
Primary Dns Suffix . . . . . . . :
Node Type . . . . . . . . . . . . : Hybrid
IP Routing Enabled. . . . . . . . : No
WINS Proxy Enabled. . . . . . . . : No
Ethernet adapter Wireless Network Connection:
Media State . . . . . . . . . . . : Media disconnected
Description . . . . . . . . . . . : 11b/g Wireless LAN Mini PCI Express Adapter III
Physical Address. . . . . . . . . : 00-24-2C-E4-E6-CF
Ethernet adapter Local Area Connection 2:
Connection-specific DNS Suffix . :
Description . . . . . . . . . . . : Intel® 82567LM Gigabit Network Connection
Physical Address. . . . . . . . . : 00-24-7E-14-8A-0D
Dhcp Enabled. . . . . . . . . . . : Yes
Autoconfiguration Enabled . . . . : Yes
IP Address. . . . . . . . . . . . : 192.168.1.5
Subnet Mask . . . . . . . . . . . : 255.255.255.0
Default Gateway . . . . . . . . . : 192.168.1.1
DHCP Server . . . . . . . . . . . : 192.168.1.1
DNS Servers . . . . . . . . . . . : 192.168.1.1
Lease Obtained. . . . . . . . . . : Tuesday, June 19, 2012 4:35:53 PM
Lease Expires . . . . . . . . . . : Wednesday, June 20, 2012 4:35:53 PM
Ethernet adapter Local Area Connection:
Media State . . . . . . . . . . . : Media disconnected
Description . . . . . . . . . . . : Ericsson F3507g Mobile Broadband Minicard Network Adapter
Physical Address. . . . . . . . . : 02-80-37-EC-02-00
Pinging google.com [74.125.224.78] with 32 bytes of data:
Reply from 74.125.224.78: bytes=32 time=17ms TTL=54
Reply from 74.125.224.78: bytes=32 time=18ms TTL=54
Ping statistics for 74.125.224.78:
Packets: Sent = 2, Received = 2, Lost = 0 (0% loss),
Approximate round trip times in milli-seconds:
Minimum = 17ms, Maximum = 18ms, Average = 17ms
Pinging yahoo.com [72.30.38.140] with 32 bytes of data:
Reply from 72.30.38.140: bytes=32 time=33ms TTL=50
Reply from 72.30.38.140: bytes=32 time=69ms TTL=50
Ping statistics for 72.30.38.140:
Packets: Sent = 2, Received = 2, Lost = 0 (0% loss),
Approximate round trip times in milli-seconds:
Minimum = 33ms, Maximum = 69ms, Average = 51ms
Pinging bleepingcomputer.com [208.43.87.2] with 32 bytes of data:
Request timed out.
Request timed out.
Ping statistics for 208.43.87.2:
Packets: Sent = 2, Received = 0, Lost = 2 (100% loss),
Pinging 127.0.0.1 with 32 bytes of data:
Reply from 127.0.0.1: bytes=32 time<1ms TTL=128
Reply from 127.0.0.1: bytes=32 time<1ms TTL=128
Ping statistics for 127.0.0.1:
Packets: Sent = 2, Received = 2, Lost = 0 (0% loss),
Approximate round trip times in milli-seconds:
Minimum = 0ms, Maximum = 0ms, Average = 0ms
===========================================================================
Interface List
0x1 ........................... MS TCP Loopback interface
0x2 ...00 24 2c e4 e6 cf ...... 11b/g Wireless LAN Mini PCI Express Adapter III - Packet Scheduler Miniport
0x3 ...00 24 7e 14 8a 0d ...... Intel® 82567LM Gigabit Network Connection - Packet Scheduler Miniport
0x10005 ...02 80 37 ec 02 00 ...... Ericsson F3507g Mobile Broadband Minicard Network Adapter - Packet Scheduler Miniport
===========================================================================
===========================================================================
Active Routes:
Network Destination Netmask Gateway Interface Metric
0.0.0.0 0.0.0.0 192.168.1.1 192.168.1.5 10
127.0.0.0 255.0.0.0 127.0.0.1 127.0.0.1 1
192.168.1.0 255.255.255.0 192.168.1.5 192.168.1.5 10
192.168.1.5 255.255.255.255 127.0.0.1 127.0.0.1 10
192.168.1.255 255.255.255.255 192.168.1.5 192.168.1.5 10
224.0.0.0 240.0.0.0 192.168.1.5 192.168.1.5 10
255.255.255.255 255.255.255.255 192.168.1.5 2 1
255.255.255.255 255.255.255.255 192.168.1.5 10005 1
255.255.255.255 255.255.255.255 192.168.1.5 192.168.1.5 1
Default Gateway: 192.168.1.1
===========================================================================
Persistent Routes:
None
========================= Winsock entries =====================================
Catalog5 01 mswsock.dll [File Not found] ()
ATTENTION: The LibraryPath should be "%SystemRoot%\System32\mswsock.dll"
Catalog5 02 C:\Windows\System32\winrnr.dll [16896] (Microsoft Corporation)
Catalog5 03 mswsock.dll [File Not found] ()
ATTENTION: The LibraryPath should be %SystemRoot%\System32\mswsock.dll
Catalog9 01 mswsock.dll [File Not found] ()
Catalog9 02 mswsock.dll [File Not found] ()
Catalog9 03 mswsock.dll [File Not found] ()
Catalog9 04 mswsock.dll [File Not found] ()
Catalog9 05 mswsock.dll [File Not found] ()
Catalog9 06 mswsock.dll [File Not found] ()
Catalog9 07 mswsock.dll [File Not found] ()
Catalog9 08 mswsock.dll [File Not found] ()
Catalog9 09 mswsock.dll [File Not found] ()
Catalog9 10 mswsock.dll [File Not found] ()
Catalog9 11 mswsock.dll [File Not found] ()
Catalog9 12 mswsock.dll [File Not found] ()
Catalog9 13 mswsock.dll [File Not found] ()
Catalog9 14 mswsock.dll [File Not found] ()
Catalog9 15 mswsock.dll [File Not found] ()
Catalog9 16 mswsock.dll [File Not found] ()
Catalog9 17 mswsock.dll [File Not found] ()
Catalog9 18 mswsock.dll [File Not found] ()
Catalog9 19 mswsock.dll [File Not found] ()
========================= Event log errors: ===============================
Application errors:
==================
Error: (06/19/2012 04:35:33 PM) (Source: MsiInstaller) (User: SYSTEM)SYSTEM
Description: Product: Microsoft Office 2000 Premium -- Error 1706. No valid source could be found for product Microsoft Office 2000 Premium. The Windows installer cannot continue.
Error: (06/19/2012 04:35:11 PM) (Source: MsiInstaller) (User: SYSTEM)SYSTEM
Description: Product: Microsoft Office 2000 Premium -- Error 1706. No valid source could be found for product Microsoft Office 2000 Premium. The Windows installer cannot continue.
Error: (06/19/2012 04:34:36 PM) (Source: MsiInstaller) (User: SYSTEM)SYSTEM
Description: Product: Microsoft Office 2000 Premium -- Error 1706. No valid source could be found for product Microsoft Office 2000 Premium. The Windows installer cannot continue.
Error: (06/19/2012 04:34:11 PM) (Source: MsiInstaller) (User: SYSTEM)SYSTEM
Description: Product: Microsoft Office 2000 Premium -- Error 1706. No valid source could be found for product Microsoft Office 2000 Premium. The Windows installer cannot continue.
Error: (06/19/2012 04:33:45 PM) (Source: MsiInstaller) (User: SYSTEM)SYSTEM
Description: Product: Microsoft Office 2000 Premium -- Error 1706. No valid source could be found for product Microsoft Office 2000 Premium. The Windows installer cannot continue.
Error: (06/19/2012 04:33:16 PM) (Source: MsiInstaller) (User: SYSTEM)SYSTEM
Description: Product: Microsoft Office 2000 Premium -- Error 1706. No valid source could be found for product Microsoft Office 2000 Premium. The Windows installer cannot continue.
Error: (06/19/2012 04:33:03 PM) (Source: MsiInstaller) (User: SYSTEM)SYSTEM
Description: Product: Microsoft Office 2000 Premium -- Error 1706. No valid source could be found for product Microsoft Office 2000 Premium. The Windows installer cannot continue.
Error: (06/19/2012 04:32:52 PM) (Source: MsiInstaller) (User: SYSTEM)SYSTEM
Description: Product: Microsoft Office 2000 Premium -- Error 1706. No valid source could be found for product Microsoft Office 2000 Premium. The Windows installer cannot continue.
Error: (06/19/2012 04:32:18 PM) (Source: MsiInstaller) (User: SYSTEM)SYSTEM
Description: Product: Microsoft Office 2000 Premium -- Error 1706. No valid source could be found for product Microsoft Office 2000 Premium. The Windows installer cannot continue.
Error: (06/19/2012 04:31:27 PM) (Source: MsiInstaller) (User: SYSTEM)SYSTEM
Description: Product: Microsoft Office 2000 Premium -- Error 1706. No valid source could be found for product Microsoft Office 2000 Premium. The Windows installer cannot continue.
System errors:
=============
Error: (06/16/2012 02:10:43 PM) (Source: DCOM) (User: Shawn)
Description: DCOM was unable to communicate with the computer D6DHVMG1 using any of the configured
protocols.
Error: (06/15/2012 10:41:08 AM) (Source: DCOM) (User: Shawn)
Description: DCOM was unable to communicate with the computer ACELLENT-PC using any of the configured
protocols.
Error: (06/15/2012 10:41:08 AM) (Source: DCOM) (User: Shawn)
Description: DCOM was unable to communicate with the computer ACELLENT-PC using any of the configured
protocols.
Error: (06/15/2012 10:41:08 AM) (Source: DCOM) (User: Shawn)
Description: DCOM was unable to communicate with the computer VINCENT_DESKTOP using any of the configured
protocols.
Error: (06/15/2012 10:41:08 AM) (Source: DCOM) (User: Shawn)
Description: DCOM was unable to communicate with the computer ACELLENT-480E6F using any of the configured
protocols.
Error: (06/15/2012 10:41:08 AM) (Source: DCOM) (User: Shawn)
Description: DCOM was unable to communicate with the computer ACELLENT-480E6F using any of the configured
protocols.
Error: (06/15/2012 10:41:08 AM) (Source: DCOM) (User: Shawn)
Description: DCOM was unable to communicate with the computer D6DHVMG1 using any of the configured
protocols.
Error: (06/15/2012 10:41:08 AM) (Source: DCOM) (User: Shawn)
Description: DCOM was unable to communicate with the computer D6DHVMG1 using any of the configured
protocols.
Error: (06/15/2012 10:40:37 AM) (Source: DCOM) (User: Shawn)
Description: DCOM was unable to communicate with the computer ACELLENT-PC using any of the configured
protocols.
Error: (06/15/2012 10:40:37 AM) (Source: DCOM) (User: Shawn)
Description: DCOM was unable to communicate with the computer ACELLENT-PC using any of the configured
protocols.
Microsoft Office Sessions:
=========================
=========================== Installed Programs ============================
4200 (Version: 40.0.105.000)
4200_Help (Version: 40.0.105.000)
4200Tour (Version: 40.0.105.000)
4200Trb (Version: 40.0.105.000)
ABBYY FineReader 6.0 Sprint (Version: 6.00.2146.41621)
Access Help (Version: 2.00)
Adobe Acrobat 6.0.1 Professional (Version: 006.000.001)
Adobe Connect Add-in
Adobe Flash Player 10 Plugin (Version: 10.0.12.36)
Adobe Flash Player 11 ActiveX (Version: 11.1.102.62)
Adobe Reader 8.3.1 (Version: 8.3.1)
AiO_Scan (Version: 40.0.105.000)
AIOMinimal (Version: 40.0.105.000)
AiOSoftware (Version: 40.0.105.000)
Android SDK Tools (Version: 0.7)
Apple Application Support (Version: 2.0.1)
Apple Software Update (Version: 2.1.3.127)
Brother HL-4070CDW (Version: 1.00)
Canon D1100 Series
Chinese Simplified Fonts Support For Adobe Reader 8 (Version: 8.0.0)
Cisco WebEx Meetings
Client Security - Password Manager (Version: 8.20.0023.00)
Compatibility Pack for the 2007 Office system (Version: 12.0.6021.5000)
Conexant HD Audio (Version: 3.53.0.0)
Copy (Version: 5.35.0.065)
CreativeProjects (Version: 5.35.0.059)
CutePDF Writer 2.8
Cypress EZ-USB, FX, FX2, SX2, and EZ-811 Dev Kit
Dell Toolbar (Version: 1.8.12.0)
Dell V310-V510 Series
Director (Version: 5.35.0.051)
DirectXInstallService (Version: 9.0.2)
DocProc (Version: 3.5.0.0)
Drag-to-Disc (Version: 9.05)
Ericsson Wireless Module Core (Version: 1.0.1046.219)
Eudora (Version: 7.0)
Fax (Version: 40.0.105.000)
FileZilla Client 3.5.3 (Version: 3.5.3)
Google Chrome (Version: 19.0.1084.56)
Google Desktop (Version: 5.9.1005.12335)
Google Earth (Version: 6.1.0.5001)
Google Quick Search Box (Version: 1.2.1151.245)
Google Toolbar for Internet Explorer (Version: 1.0.0)
Google Toolbar for Internet Explorer (Version: 7.3.2710.138)
Google Update Helper (Version: 1.3.21.111)
Google Updater (Version: 2.4.2432.1652)
GoToMeeting 4.5.0.457
Help Center (Version: 2.00h)
High Definition Audio Driver Package - KB888111 (Version: 20040219.000000)
HP Image Zone 3.5 (Version: 3.5)
hp LaserJet 1160/1320 series (Version: 1.00.0000)
HP PSC & OfficeJet 3.5 (Version: 3.5)
HP Software Update (Version: 2.0.38.20040107)
HP Unload DLL Patch (Version: 1.00.0000)
HPSystemDiagnostics (Version: 1.5.0.0)
InstantShare (Version: 3.5.0.21)
Intel® Graphics Media Accelerator Driver
Intel® Management Engine Interface
Intel® Network Connections Drivers
Intel® Active Management Technology
Intel® Trusted Platform Module
interneTIFF 8.0-FREE (IE Browser) (Version: 8.00.00.0)
InterVideo Register Manager (Version: 1.0.4.0)
InterVideo WinDVD (Version: 5.0-B11.1243)
J2SE Runtime Environment 5.0 Update 16 (Version: 1.5.0.160)
Java Auto Updater (Version: 2.1.5.1)
Java 6 Update 20 (Version: 6.0.200)
Java 7 (Version: 7.0.0)
Java SE Development Kit 7 (Version: 1.7.0.0)
JT2Go (Version: 8.3.11020)
Lenovo Central Audio (Version: 3.7.0)
Lenovo Registration
Lenovo System Toolbox (Version: 5.1.5183.14)
Malwarebytes Anti-Malware version 1.61.0.1400 (Version: 1.61.0.1400)
MATLAB 6.5
Message Center (Version: 2.01d)
Microsoft .NET Framework 1.1 (Version: 1.1.4322)
Microsoft .NET Framework 1.1 Security Update (KB2656353)
Microsoft .NET Framework 1.1 Security Update (KB2656370)
Microsoft .NET Framework 1.1 Security Update (KB979906)
Microsoft .NET Framework 2.0 Service Pack 2 (Version: 2.2.30729)
Microsoft .NET Framework 3.0 Service Pack 2 (Version: 3.2.30729)
Microsoft .NET Framework 3.5 SP1
Microsoft .NET Framework 3.5 SP1 (Version: 3.5.30729)
Microsoft Internationalized Domain Names Mitigation APIs
Microsoft National Language Support Downlevel APIs
Microsoft Office 2000 Premium (Version: 9.00.2720)
Microsoft SQL Server Native Client (Version: 9.00.3042.00)
Microsoft SQL Server Setup Support Files (English) (Version: 9.00.3042.00)
Microsoft Visual C++ 2005 Redistributable (Version: 8.0.56336)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.5026 (Version: 9.0.30729.5026)
Mobile Broadband Connect (Version: 3.4.0058)
MSXML 4.0 SP2 (KB927978) (Version: 4.20.9841.0)
MSXML 4.0 SP2 (KB954430) (Version: 4.20.9870.0)
MSXML 4.0 SP2 (KB973688) (Version: 4.20.9876.0)
MSXML 6.0 Parser (Version: 6.10.1129.0)
NETGEAR USB Control Center (Version: 1.11)
On Screen Display (Version: 5.21.00)
Oracle Web Conferencing Console
Overland (Version: 2.1.4)
overland (Version: 2.1.5)
PhotoGallery (Version: 5.35.0.059)
PL-2303 USB-to-Serial (Version: 1.5.0)
Presentation Director (Version: 4.00a)
PrimoPDF -- by Nitro PDF Software (Version: 5.0.0.19)
PrintScreen (Version: 5.40.10.000)
Productivity Center Supplement for ThinkPad (Version: 3.00b)
QFolder (Version: 1.00.0000)
QuickProjects (Version: 5.35.0.047)
QuickTime (Version: 7.70.80.34)
R for Windows 2.13.0 (Version: 2.13.0)
Readme (Version: 40.0.105.000)
Remote Administrator v2.1
Rescue and Recovery (Version: 4.21.0030.00)
RICOH R5C83x/84x Flash Media Controller Driver Ver.3.54.02 (Version: 3.54.02)
Roxio Central Copy (Version: 3.7.0)
Roxio Central Core (Version: 3.7.0)
Roxio Central Data (Version: 3.7.0)
Roxio Central Tools (Version: 3.7.0)
Roxio Creator Business Edition (Version: 10.1)
Roxio Creator Business Edition (Version: 10.1.171)
Roxio Express Labeler 3 (Version: 3.2.1)
Scan (Version: 3.5.0.0)
SkinsHP1 (Version: 5.35.0.043)
SkinsHP2 (Version: 5.35.0.043)
Skype Click to Call (Version: 6.0.10201)
Skype™ 5.8 (Version: 5.8.158)
Sonic CinePlayer Decoder Pack (Version: 4.3.0)
Sonic Icons for Lenovo (Version: 2.0.0)
System Update (Version: 3.14.0034)
ThinkPad 11a/b/g/n Wireless LAN Mini-PCI Express Adapter (Version: 7.4.2.105b)
ThinkPad Bluetooth with Enhanced Data Rate Software (Version: 5.5.0.3100)
ThinkPad EasyEject Utility (Version: 2.36)
ThinkPad FullScreen Magnifier (Version: 2.04)
ThinkPad Modem Adapter (Version: 7.73.00)
ThinkPad PC Card Power Policy (Version: 1.02)
ThinkPad Power Management Driver (Version: 1.45)
ThinkPad Power Manager (Version: 1.52)
ThinkPad UltraNav Driver (Version: 11.1.21.2)
ThinkPad UltraNav Utility (Version: 2.04)
ThinkVantage Access Connections (Version: 5.21)
ThinkVantage Active Protection System (Version: 1.61)
ThinkVantage GPS (Version: 2.11)
ThinkVantage Productivity Center (Version: 3.02)
ThinkVantage Technologies Welcome Message (Version: 1.20)
TrayApp (Version: 5.35.0.035)
Unload (Version: 3.5.0)
Update for Microsoft .NET Framework 3.5 SP1 (KB963707) (Version: 1)
Update for Windows Internet Explorer 7 (KB976749) (Version: 1)
Update for Windows Internet Explorer 8 (KB976662) (Version: 1)
Update for Windows Internet Explorer 8 (KB978506) (Version: 1)
Update for Windows Internet Explorer 8 (KB980182) (Version: 1)
Update for Windows XP (KB2141007) (Version: 1)
Update for Windows XP (KB2345886) (Version: 1)
Update for Windows XP (KB2467659) (Version: 1)
Update for Windows XP (KB2541763) (Version: 1)
Update for Windows XP (KB2616676-v2) (Version: 2)
Update for Windows XP (KB2616676) (Version: 1)
Update for Windows XP (KB2641690) (Version: 1)
Update for Windows XP (KB2718704) (Version: 1)
Update for Windows XP (KB951978) (Version: 1)
Update for Windows XP (KB955759) (Version: 1)
Update for Windows XP (KB955839) (Version: 1)
Update for Windows XP (KB967715) (Version: 1)
Update for Windows XP (KB968389) (Version: 1)
Update for Windows XP (KB971029) (Version: 1)
Update for Windows XP (KB971737) (Version: 1)
Update for Windows XP (KB973687) (Version: 1)
Update for Windows XP (KB973815) (Version: 1)
uVision2
Verizon Wireless BroadbandAccess Self Activation (Version: 1.3.2)
Wallpapers
WD SmartWare (Version: 1.5.4)
WebFldrs XP (Version: 9.50.7523)
WebReg (Version: 5.31.0.147)
Windows Genuine Advantage Notifications (KB905474) (Version: 1.9.0040.0)
Windows Genuine Advantage Validation Tool (KB892130)
Windows Genuine Advantage Validation Tool (KB892130) (Version: 1.7.0069.2)
Windows Imaging Component (Version: 3.0.0.0)
Windows Internet Explorer 7 (Version: 20061107.210142)
Windows Internet Explorer 8 (Version: 20090308.140743)
Windows Media Connect
Windows Media Format Runtime
Windows Media Player 10
Windows Presentation Foundation (Version: 3.0.6920.0)
Windows XP Service Pack 3 (Version: 20080414.031525)
WinZip 12.0 (Version: 12.0.8252)
XML Paper Specification Shared Components Pack 1.0
XP Themes (Version: 1.00.0000)
========================= Devices: ================================
========================= Memory info: ===================================
Percentage of memory in use: 46%
Total physical RAM: 3015.95 MB
Available physical RAM: 1599.22 MB
Total Pagefile: 4901.02 MB
Available Pagefile: 3552.07 MB
Total Virtual: 2047.88 MB
Available Virtual: 1968.3 MB
========================= Partitions: =====================================
1 Drive c: (Preload) (Fixed) (Total:226.74 GB) (Free:111.21 GB) NTFS
========================= Users: ========================================
User accounts for \\LENOVO-641B743A
Administrator ASPNET Guest
HelpAssistant Shawn SUPPORT_388945a0
**** End of log ****
__________________________________________________________________
aswMBR version 0.9.9.1665 Copyright© 2011 AVAST Software
Run date: 2012-06-19 16:55:31
-----------------------------
16:55:31.359 OS Version: Windows 5.1.2600 Service Pack 3
16:55:31.359 Number of processors: 2 586 0x170A
16:55:31.359 ComputerName: LENOVO-641B743A UserName: Shawn
16:55:33.890 Initialize success
16:57:57.015 AVAST engine defs: 12061901
16:58:49.125 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1
16:58:49.125 Disk 0 Vendor: HITACHI_ FBEZ Size: 238475MB BusType: 3
16:58:49.156 Disk 0 MBR read successfully
16:58:49.171 Disk 0 MBR scan
16:58:49.218 Disk 0 unknown MBR code
16:58:49.250 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 232185 MB offset 2048
16:58:49.265 Disk 0 Partition 2 00 12 Compaq diag MSDOS5.0 6288 MB offset 475516928
16:58:49.281 Disk 0 scanning sectors +488394752
16:58:49.359 Disk 0 scanning C:\WINDOWS\system32\drivers
16:58:58.687 File: C:\WINDOWS\system32\drivers\i8042prt.sys **INFECTED** Win32:Sirefef-PL [Rtk]
16:59:06.500 Disk 0 trace - called modules:
16:59:06.546 ntkrnlpa.exe CLASSPNP.SYS disk.sys >>UNKNOWN [0xba1cb698]<<
16:59:06.562 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x8ac04ab8]
16:59:06.562 3 CLASSPNP.SYS[ba0e8fd7] -> nt!IofCallDriver -> [0x8a053f08]
16:59:06.562 \Driver\00001596[0x8a0e1cc8] -> IRP_MJ_CREATE -> 0xba1cb698
16:59:08.484 AVAST engine scan C:\WINDOWS
16:59:31.843 AVAST engine scan C:\WINDOWS\system32
17:02:49.609 AVAST engine scan C:\WINDOWS\system32\drivers
17:03:01.296 File: C:\WINDOWS\system32\drivers\i8042prt.sys **INFECTED** Win32:Sirefef-PL [Rtk]
17:03:28.578 AVAST engine scan C:\Documents and Settings\Shawn
17:48:19.437 File: C:\Documents and Settings\Shawn\Application Data\sbrig.dll **INFECTED** Win32:Medfos-Y [Trj]
17:48:54.437 File: C:\Documents and Settings\Shawn\Application Data\thizc.dll **INFECTED** Win32:Agent-AONR [Trj]
18:00:39.046 File: C:\Documents and Settings\Shawn\Local Settings\Temp\jure221893.exe **INFECTED** Win32:FakeSysdefs-D [Trj]
18:20:59.921 AVAST engine scan C:\Documents and Settings\All Users
18:23:41.890 Scan finished successfully
18:23:57.828 Disk 0 MBR has been saved successfully to "C:\Documents and Settings\Shawn\Desktop\MBR.dat"
18:23:57.875 The log file has been saved successfully to "C:\Documents and Settings\Shawn\Desktop\aswMBR.txt"


Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.
Back to top








