As the title suggests, I came under attack from a virut virus. As soon as Mcafee saw the virus, Mcafee started quarantining everything while a few porn links popped up on my desktop. It was then that I pulled the network connection and hard shut down the computer (power button held down).
I used UBCD with the western digital tool to perform a low level format on my two WD drives, and as for my seagate drive I deleted the mbr and partitions and performed a format on it; Seatools wouldn't work, nor did Killdisk nor Dban for whatever reason.
I've then reinstalled XP, ran the UBCD with Dr Web Cureit as well as the other AntiVirus programs on the CD. They all came up clean. Mcafee, updated with latest definitions, in the new XP install also says 'clean'.
I have now run all the logs after installing a few things, still no signs of the virut so It doesn't seem to show any signs of the virus rising from the dead (rootkit), but I NEED to be as certain as possible!
I feel so violated, as if my house was broken into; I just still don't feel safe. I hope someone here can help me sleep at night!
DDS (Ver_09-12-01.01) - NTFSx86
Run by AkaiKishi at 23:43:34.15 on Mon 12/07/2009
Internet Explorer: 8.0.6001.18702
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3326.2567 [GMT -5:00]
AV: McAfee VirusScan Enterprise *On-access scanning enabled* (Updated) {918A2B0B-2C60-4016-A4AB-E868DEABF7F0}
============== Running Processes ===============
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
D:\Program Files\Creative\Shared Files\CTAudSvc.exe
C:\WINDOWS\Explorer.EXE
D:\Program Files\McAfee\VirusScan Enterprise\SHSTAT.EXE
D:\Program Files\McAfee\Common Framework\UdaterUI.exe
D:\Program Files\ITE\Smart Guardian\ITESMART.exe
C:\WINDOWS\system32\CTHELPER.EXE
D:\Program Files\Creative\DVDAudio\CTDVDDET.EXE
C:\WINDOWS\system32\ctfmon.exe
D:\Program Files\RivaTuner v2.24\RivaTuner.exe
D:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
svchost.exe
D:\Program Files\McAfee\Common Framework\FrameworkService.exe
D:\Program Files\McAfee\Common Framework\McTray.exe
D:\Program Files\McAfee\VirusScan Enterprise\mcshield.exe
D:\Program Files\McAfee\VirusScan Enterprise\vstskmgr.exe
D:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
D:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\AkaiKishi\Desktop\RootRepeal.exe
C:\Documents and Settings\AkaiKishi\Desktop\dds.scr
============== Pseudo HJT Report ===============
uStart Page = about:blank
uInternet Connection Wizard,ShellNext = hxxp://google.com/
BHO: scriptproxy: {7db2d5a0-7241-4e79-b68d-6309f01c5231} - d:\program files\mcafee\virusscan enterprise\Scriptcl.dll
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
mRun: [IMJPMIG8.1] "c:\windows\ime\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
mRun: [PHIME2002ASync] c:\windows\system32\ime\tintlgnt\TINTSETP.EXE /SYNC
mRun: [PHIME2002A] c:\windows\system32\ime\tintlgnt\TINTSETP.EXE /IMEName
mRun: [ShStatEXE] "d:\program files\mcafee\virusscan enterprise\SHSTAT.EXE" /STANDALONE
mRun: [McAfeeUpdaterUI] "d:\program files\mcafee\common framework\UdaterUI.exe" /StartedFromRunKey
mRun: [SmartGuardian] d:\program files\ite\smart guardian\ITESMART.exe
mRun: [StartCCC] "d:\program files\ati technologies\ati.ace\core-static\CLIStart.exe" MSRun
mRun: [CTHelper] CTHELPER.EXE
mRun: [CTDVDDET] "d:\program files\creative\dvdaudio\CTDVDDET.EXE"
mRun: [RivaTunerStartupDaemon] "d:\program files\rivatuner v2.24\RivaTuner.exe" /S
dRunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N
StartupFolder: c:\docume~1\akaiki~1\startm~1\programs\startup\rivatu~1.lnk - d:\program files\rivatuner v2.24\RivaTuner.exe
uPolicies-explorer: ForceClassicControlPanel = 1 (0x1)
uPolicies-explorer: NoSMMyDocs = 1 (0x1)
uPolicies-explorer: NoSMMyPictures = 1 (0x1)
uPolicies-explorer: NoSMHelp = 1 (0x1)
uPolicies-explorer: NoSMConfigurePrograms = 1 (0x1)
mPolicies-system: DisableCAD = 1 (0x1)
dPolicies-explorer: ForceClassicControlPanel = 1 (0x1)
dPolicies-explorer: NoSMMyDocs = 1 (0x1)
dPolicies-explorer: NoSMMyPictures = 1 (0x1)
dPolicies-explorer: NoSMHelp = 1 (0x1)
dPolicies-explorer: NoSMConfigurePrograms = 1 (0x1)
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
DPF: {6C269571-C6D7-4818-BCA4-32A035E8C884} - hxxp://ccfiles.creative.com/Web/softwareupdate/su/ocx/15101/CTSUEng.cab
DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} - hxxp://ccfiles.creative.com/Web/softwareupdate/su/ocx/15110/CTPID.cab
Notify: AtiExtEvent - Ati2evxx.dll
Hosts: 127.0.0.1 www.spywareinfo.com
================= FIREFOX ===================
FF - ProfilePath - c:\docume~1\akaiki~1\applic~1\mozilla\firefox\profiles\s3atc122.default\
FF - prefs.js: browser.startup.homepage - www.google.com
FF - plugin: c:\documents and settings\akaikishi\application data\mozilla\firefox\profiles\s3atc122.default\extensions\iaplayer@instantaction.com\plugins\npiaplayer.dll
FF - plugin: c:\program files\windows media player\npdrmv2.dll
FF - plugin: c:\program files\windows media player\npdsplay.dll
FF - plugin: c:\program files\windows media player\npwmsdrm.dll
---- FIREFOX POLICIES ----
d:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
============= SERVICES / DRIVERS ===============
R2 McAfeeFramework;McAfee Framework Service;d:\program files\mcafee\common framework\FrameworkService.exe [2009-12-7 104000]
R2 McShield;McAfee McShield;d:\program files\mcafee\virusscan enterprise\mcshield.exe [2009-1-27 144704]
R2 McTaskManager;McAfee Task Manager;d:\program files\mcafee\virusscan enterprise\vstskmgr.exe [2009-1-27 54608]
R3 COMMONFX.SYS;COMMONFX.SYS;c:\windows\system32\drivers\COMMONFX.sys [2009-12-7 99416]
R3 CTAUDFX.SYS;CTAUDFX.SYS;c:\windows\system32\drivers\CTAUDFX.sys [2009-12-7 555096]
R3 ctgame;Game Port;c:\windows\system32\drivers\ctgame.sys [2009-12-7 18904]
R3 CTSBLFX.SYS;CTSBLFX.SYS;c:\windows\system32\drivers\CTSBLFX.sys [2009-12-7 566360]
R3 mfeavfk;McAfee Inc.;c:\windows\system32\drivers\mfeavfk.sys [2009-12-7 73512]
R3 mfebopk;McAfee Inc.;c:\windows\system32\drivers\mfebopk.sys [2009-12-7 34408]
R3 mfehidk;McAfee Inc.;c:\windows\system32\drivers\mfehidk.sys [2009-12-7 177864]
S3 COMMONFX;COMMONFX;c:\windows\system32\drivers\COMMONFX.sys [2009-12-7 99416]
S3 Creative Dolby Digital Live Pack Licensing Service;Creative Dolby Digital Live Pack Licensing Service;c:\program files\common files\creative labs shared\service\DDLLicensing.exe [2009-12-7 79360]
S3 CTAUDFX;CTAUDFX;c:\windows\system32\drivers\CTAUDFX.sys [2009-12-7 555096]
S3 CTERFXFX.SYS;CTERFXFX.SYS;c:\windows\system32\drivers\CTERFXFX.sys [2009-12-7 100952]
S3 CTERFXFX;CTERFXFX;c:\windows\system32\drivers\CTERFXFX.sys [2009-12-7 100952]
S3 CTSBLFX;CTSBLFX;c:\windows\system32\drivers\CTSBLFX.sys [2009-12-7 566360]
=============== Created Last 30 ================
2009-12-08 03:10:54 1080 ----a-w- c:\windows\system32\settingsbkup.sfm
2009-12-08 03:10:54 1080 ----a-w- c:\windows\system32\settings.sfm
2009-12-08 03:02:50 0 d-----w- c:\docume~1\akaiki~1\applic~1\GarageGames
2009-12-08 02:42:09 0 d-----w- d:\program files\RivaTuner v2.24
2009-12-08 02:19:12 218624 ----a-w- c:\windows\system32\uxtheme.uxtender
2009-12-08 02:06:59 7062 ----a-w- c:\windows\system32\audiopid.vxd
2009-12-08 01:42:36 33552 ----a-w- c:\windows\system32\BMXCtrlState-{00000005-00000000-00000002-00001102-00000004-20021102}.rfx
2009-12-08 01:42:36 33552 ----a-w- c:\windows\system32\BMXBkpCtrlState-{00000005-00000000-00000002-00001102-00000004-20021102}.rfx
2009-12-08 01:42:36 32976 ----a-w- c:\windows\system32\BMXStateBkp-{00000005-00000000-00000002-00001102-00000004-20021102}.rfx
2009-12-08 01:42:36 32976 ----a-w- c:\windows\system32\BMXState-{00000005-00000000-00000002-00001102-00000004-20021102}.rfx
2009-12-08 01:42:36 11564 ----a-w- c:\windows\system32\DVCState-{00000005-00000000-00000002-00001102-00000004-20021102}.rfx
2009-12-08 01:42:27 4932846 ------w- c:\windows\{00000005-00000000-00000002-00001102-00000004-20021102}.BAK
2009-12-08 01:39:44 0 d-----w- c:\program files\common files\Creative Labs Shared
2009-12-08 01:39:37 61440 ------w- c:\windows\system32\CTChkAud.dll
2009-12-08 01:39:37 6010 ------w- c:\windows\system32\CTOPT352.cat
2009-12-08 01:39:37 171680 ------w- c:\windows\system32\CTOPT352.dll
2009-12-08 01:37:29 65536 ------w- c:\windows\system32\ctdvda32.dll
2009-12-08 01:37:29 1746360 ------w- c:\windows\system32\CTAA1.DAT
2009-12-08 01:31:47 7572224 ------w- c:\windows\system32\CT8MGM.SF2
2009-12-08 01:31:47 4174814 ------w- c:\windows\system32\CT4MGM.SF2
2009-12-08 01:31:47 0 d-----w- c:\windows\system32\Defaults
2009-12-08 01:31:14 4932846 ----a-w- c:\windows\{00000005-00000000-00000002-00001102-00000004-20021102}.CDF
2009-12-08 01:31:07 444952 ----a-w- c:\windows\system32\wrap_oal.dll
2009-12-08 01:31:07 109080 ----a-w- c:\windows\system32\OpenAL32.dll
2009-12-08 01:30:46 0 d-----w- d:\program files\Creative
2009-12-08 01:30:46 0 d-----w- c:\windows\system32\Data
2009-12-08 01:28:35 6400 -c--a-w- c:\windows\system32\dllcache\enum1394.sys
2009-12-08 01:28:35 6400 ----a-w- c:\windows\system32\drivers\enum1394.sys
2009-12-08 01:28:20 61696 -c--a-w- c:\windows\system32\dllcache\ohci1394.sys
2009-12-08 01:28:20 61696 ----a-w- c:\windows\system32\drivers\ohci1394.sys
2009-12-08 01:28:19 53376 -c--a-w- c:\windows\system32\dllcache\1394bus.sys
2009-12-08 01:28:19 53376 ----a-w- c:\windows\system32\drivers\1394bus.sys
2009-12-08 01:14:56 60800 -c--a-w- c:\windows\system32\dllcache\sysaudio.sys
2009-12-08 00:30:17 189528 ----a-w- c:\windows\system32\drivers\haP17v2k.sys
2009-12-07 22:46:36 0 d-----w- d:\program files\Spybot - Search & Destroy
2009-12-07 22:46:36 0 d-----w- c:\docume~1\alluse~1\applic~1\Spybot - Search & Destroy
2009-12-07 18:34:00 887724 ----a-w- c:\windows\system32\ativva6x.dat
2009-12-07 18:34:00 7167 ----a-w- c:\windows\system32\atifglpf.xml
2009-12-07 18:34:00 479232 ----a-w- c:\windows\system32\ATIDEMGX.dll
2009-12-07 18:33:59 18618 ----a-w- c:\windows\atiogl.xml
2009-12-07 18:33:58 311296 ----a-w- c:\windows\system32\atiiiexx.dll
2009-12-07 18:33:58 3 ----a-w- c:\windows\system32\ativva5x.dat
2009-12-07 18:33:58 195855 ----a-w- c:\windows\system32\atiicdxx.dat
2009-12-07 18:33:33 0 d-----w- d:\program files\ATI Technologies
2009-12-07 18:29:29 0 d-sh--w- c:\documents and settings\akaikishi\PrivacIE
2009-12-07 18:26:49 0 d-sh--w- c:\documents and settings\akaikishi\IETldCache
2009-12-07 18:24:53 0 d-----w- c:\windows\ie8updates
2009-12-07 18:24:50 594432 -c----w- c:\windows\system32\dllcache\msfeeds.dll
2009-12-07 18:24:50 55296 -c----w- c:\windows\system32\dllcache\msfeedsbs.dll
2009-12-07 18:24:50 246272 -c----w- c:\windows\system32\dllcache\ieproxy.dll
2009-12-07 18:24:50 1985536 -c----w- c:\windows\system32\dllcache\iertutil.dll
2009-12-07 18:24:50 12800 -c----w- c:\windows\system32\dllcache\xpshims.dll
2009-12-07 18:24:50 11069440 -c----w- c:\windows\system32\dllcache\ieframe.dll
2009-12-07 18:23:57 0 dc-h--w- c:\windows\ie8
2009-12-07 12:15:14 272128 -c----w- c:\windows\system32\dllcache\bthport.sys
2009-12-07 12:15:14 272128 ------w- c:\windows\system32\drivers\bthport.sys
2009-12-07 12:02:23 455296 -c----w- c:\windows\system32\dllcache\mrxsmb.sys
2009-12-07 11:59:25 0 d-----w- d:\program files\Seagate
2009-12-07 11:59:17 2145280 -c----w- c:\windows\system32\dllcache\ntkrnlmp.exe
2009-12-07 11:59:17 2023936 -c----w- c:\windows\system32\dllcache\ntkrpamp.exe
2009-12-07 11:59:16 2066048 -c----w- c:\windows\system32\dllcache\ntkrnlpa.exe
2009-12-07 11:57:05 0 d-sh--w- c:\documents and settings\akaikishi\UserData
2009-12-07 11:56:06 0 d-----w- d:\program files\ATI
2009-12-07 11:55:52 14048 ------w- c:\windows\system32\spmsg2.dll
2009-12-07 11:54:50 0 d-----w- c:\windows\system32\PreInstall
2009-12-07 11:54:49 26144 ----a-w- c:\windows\system32\spupdsvc.exe
2009-12-07 11:54:48 0 d--h--w- c:\windows\$hf_mig$
2009-12-07 11:54:35 0 d-----w- C:\ATI
2009-12-07 11:50:51 0 d-----w- c:\windows\system32\SoftwareDistribution
2009-12-07 11:45:46 280 ----a-w- c:\windows\system32\epoPGPsdk.dll.sig
2009-12-07 11:45:33 73512 ----a-w- c:\windows\system32\drivers\mfeavfk.sys
2009-12-07 11:45:33 65000 ----a-w- c:\windows\system32\drivers\mfeapfk.sys
2009-12-07 11:45:33 52168 ----a-w- c:\windows\system32\drivers\mfetdik.sys
2009-12-07 11:45:33 34408 ----a-w- c:\windows\system32\drivers\mfebopk.sys
2009-12-07 11:45:33 177864 ----a-w- c:\windows\system32\drivers\mfehidk.sys
2009-12-07 11:45:28 0 d-----w- d:\program files\McAfee
2009-12-07 11:45:28 0 d-----w- c:\program files\common files\McAfee
2009-12-07 11:43:03 0 d-----w- c:\windows\system32\appmgmt
2009-12-07 11:39:44 499712 ----a-w- c:\windows\system32\msvcp71.dll
2009-12-07 11:39:44 348160 ----a-w- c:\windows\system32\msvcr71.dll
2009-12-07 11:39:44 1495552 ----a-w- c:\windows\system32\epoPGPsdk.dll
2009-12-07 11:39:44 0 d-----w- c:\program files\common files\Cisco Systems
2009-12-07 11:34:08 0 d-----w- d:\program files\windows nt
2009-12-07 11:34:08 0 d-----w- d:\program files\msn gaming zone
2009-12-07 11:33:12 0 d-----w- c:\program files\common files\Wise Installation Wizard
2009-12-07 11:32:57 118784 ----a-r- c:\windows\system32\Msstdfmt.dll
2009-12-07 11:32:57 1066176 ----a-w- c:\windows\system32\Mscomctl.ocx
2009-12-07 11:32:56 6080 ----a-w- c:\windows\system32\drivers\zntport.sys
2009-12-07 11:32:56 46080 ----a-r- c:\windows\system32\itevio.dll
2009-12-07 11:32:56 112 ----a-w- c:\windows\system32\drivers\a.bat
2009-12-07 11:32:56 102912 ----a-r- c:\windows\system32\Ntport.dll
2009-12-07 11:32:56 0 d-----w- d:\program files\ITE
2009-12-07 11:32:56 0 d-----w- c:\windows\SysWow64
2009-12-07 11:32:19 0 d-----w- d:\program files\Marvell
2009-12-07 11:32:11 0 d-----w- c:\program files\common files\InstallShield
2009-12-07 11:30:47 0 d-----w- c:\windows\system32\ReinstallBackups
2009-12-07 11:30:27 0 d-----w- C:\Intel
2009-12-07 11:16:57 0 d-----w- c:\windows\system32\NtmsData
2009-12-07 05:24:24 0 d-sh--w- c:\documents and settings\all users\DRM
2009-12-07 05:23:46 0 d-----w- c:\program files\common files\MSSoap
2009-12-07 00:18:10 0 d-----w- c:\program files\common files\ODBC
2009-12-07 00:18:08 0 d-----w- c:\program files\common files\SpeechEngines
2009-12-07 00:16:54 0 d-----r- c:\documents and settings\all users\Documents
==================== Find3M ====================
2009-12-08 02:19:12 218624 ----a-w- c:\windows\system32\uxtheme.dll
2009-12-07 05:22:59 21640 ----a-w- c:\windows\system32\emptyregdb.dat
2009-11-04 16:15:30 4423168 ----a-w- c:\windows\system32\drivers\ati2mtag.sys
2009-11-04 15:44:14 300032 ----a-w- c:\windows\system32\ati2dvag.dll
2009-11-04 15:29:44 204800 ----a-w- c:\windows\system32\atipdlxx.dll
2009-11-04 15:29:28 155648 ----a-w- c:\windows\system32\Oemdspif.dll
2009-11-04 15:29:16 26112 ----a-w- c:\windows\system32\Ati2mdxx.exe
2009-11-04 15:29:08 43520 ----a-w- c:\windows\system32\ati2edxx.dll
2009-11-04 15:28:54 155648 ----a-w- c:\windows\system32\ati2evxx.dll
2009-11-04 15:27:40 602112 ----a-w- c:\windows\system32\ati2evxx.exe
2009-11-04 15:26:18 53248 ----a-w- c:\windows\system32\ATIDDC.DLL
2009-11-04 15:18:50 3518304 ----a-w- c:\windows\system32\ati3duag.dll
2009-11-04 15:17:48 13000704 ----a-w- c:\windows\system32\atioglxx.dll
2009-11-04 15:05:10 2135680 ----a-w- c:\windows\system32\ativvaxx.dll
2009-11-04 14:51:08 65024 ----a-w- c:\windows\system32\atimpc32.dll
2009-11-04 14:51:08 65024 ----a-w- c:\windows\system32\amdpcom32.dll
2009-11-04 14:47:16 565248 ----a-w- c:\windows\system32\atikvmag.dll
2009-11-04 14:46:58 45056 ----a-w- c:\windows\system32\aticalrt.dll
2009-11-04 14:46:44 45056 ----a-w- c:\windows\system32\aticalcl.dll
2009-11-04 14:45:30 172032 ----a-w- c:\windows\system32\atiadlxx.dll
2009-11-04 14:45:08 3526656 ----a-w- c:\windows\system32\aticaldd.dll
2009-11-04 14:45:04 17408 ----a-w- c:\windows\system32\atitvo32.dll
2009-11-04 14:44:48 397312 ----a-w- c:\windows\system32\atiok3x2.dll
2009-11-04 14:44:20 53248 ----a-w- c:\windows\system32\drivers\ati2erec.dll
2009-11-04 14:39:26 638976 ----a-w- c:\windows\system32\ati2cqag.dll
2009-10-02 21:19:30 623962 ----a-w- c:\windows\system32\UDAAIM32.exe
2009-09-23 21:19:34 43520 ----a-w- c:\windows\system32\CTBurst.dll
2009-09-23 21:19:16 11776 ----a-w- c:\windows\system32\inres.dll
2009-09-23 21:19:16 11776 ----a-w- c:\windows\INRES.DLL
2009-09-23 21:19:12 86528 ----a-w- c:\windows\system32\ctcoinst.dll
2009-09-23 21:19:12 182272 ----a-w- c:\windows\system32\ctdvinst.dll
2009-09-23 21:18:08 10752 ----a-w- c:\windows\system32\a3d.dll
2009-09-23 21:06:36 51787 ----a-w- c:\windows\system32\ctdlang.dat
2009-09-23 21:06:36 386852 ----a-w- c:\windows\system32\ctdnlstr.dat
2009-09-23 21:06:00 196096 ----a-w- c:\windows\system32\ctemupia.dll
2009-09-23 21:03:28 176128 ----a-w- c:\windows\system32\ct_oal.dll
2009-09-23 21:03:26 46592 ----a-w- c:\windows\system32\ctasio.dll
2009-09-23 21:03:22 49152 ----a-w- c:\windows\system32\ctdproxy.dll
2009-09-23 21:03:04 69632 ----a-w- c:\windows\system32\ctosuser.dll
2009-09-23 21:03:02 6144 ----a-w- c:\windows\system32\sfman32.dll
2009-09-23 21:02:58 125952 ----a-w- c:\windows\system32\sfms32.dll
2009-09-23 21:02:54 13312 ----a-w- c:\windows\system32\regplib.exe
2009-09-23 21:02:52 64512 ----a-w- c:\windows\system32\piaproxy.dll
2009-09-23 21:01:54 149838 ----a-w- c:\windows\system32\ctbas2w.dat
2009-09-23 21:00:24 274587 ----a-w- c:\windows\system32\ctsbas2w.dat
2009-09-23 20:59:38 53932 ----a-w- c:\windows\system32\ctdaught.dat
2009-09-23 20:59:36 313207 ----a-w- c:\windows\system32\ctstatic.dat
2009-09-23 20:59:34 5120 ----a-w- c:\windows\system32\enlocstr.exe
2009-09-23 20:59:30 10240 ----a-w- c:\windows\system32\killapps.exe
2009-09-23 20:59:10 28672 ----a-w- c:\windows\system32\MIDIDEF.EXE
2009-09-23 20:59:08 33792 ----a-w- c:\windows\system32\devreg.dll
2009-09-11 14:18:39 136192 ----a-w- c:\windows\system32\msv1_0.dll
============= FINISH: 23:43:53.56 ===============
I used UBCD with the western digital tool to perform a low level format on my two WD drives, and as for my seagate drive I deleted the mbr and partitions and performed a format on it; Seatools wouldn't work, nor did Killdisk nor Dban for whatever reason.
I've then reinstalled XP, ran the UBCD with Dr Web Cureit as well as the other AntiVirus programs on the CD. They all came up clean. Mcafee, updated with latest definitions, in the new XP install also says 'clean'.
I have now run all the logs after installing a few things, still no signs of the virut so It doesn't seem to show any signs of the virus rising from the dead (rootkit), but I NEED to be as certain as possible!
I feel so violated, as if my house was broken into; I just still don't feel safe. I hope someone here can help me sleep at night!
DDS (Ver_09-12-01.01) - NTFSx86
Run by AkaiKishi at 23:43:34.15 on Mon 12/07/2009
Internet Explorer: 8.0.6001.18702
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3326.2567 [GMT -5:00]
AV: McAfee VirusScan Enterprise *On-access scanning enabled* (Updated) {918A2B0B-2C60-4016-A4AB-E868DEABF7F0}
============== Running Processes ===============
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
D:\Program Files\Creative\Shared Files\CTAudSvc.exe
C:\WINDOWS\Explorer.EXE
D:\Program Files\McAfee\VirusScan Enterprise\SHSTAT.EXE
D:\Program Files\McAfee\Common Framework\UdaterUI.exe
D:\Program Files\ITE\Smart Guardian\ITESMART.exe
C:\WINDOWS\system32\CTHELPER.EXE
D:\Program Files\Creative\DVDAudio\CTDVDDET.EXE
C:\WINDOWS\system32\ctfmon.exe
D:\Program Files\RivaTuner v2.24\RivaTuner.exe
D:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
svchost.exe
D:\Program Files\McAfee\Common Framework\FrameworkService.exe
D:\Program Files\McAfee\Common Framework\McTray.exe
D:\Program Files\McAfee\VirusScan Enterprise\mcshield.exe
D:\Program Files\McAfee\VirusScan Enterprise\vstskmgr.exe
D:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
D:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\AkaiKishi\Desktop\RootRepeal.exe
C:\Documents and Settings\AkaiKishi\Desktop\dds.scr
============== Pseudo HJT Report ===============
uStart Page = about:blank
uInternet Connection Wizard,ShellNext = hxxp://google.com/
BHO: scriptproxy: {7db2d5a0-7241-4e79-b68d-6309f01c5231} - d:\program files\mcafee\virusscan enterprise\Scriptcl.dll
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
mRun: [IMJPMIG8.1] "c:\windows\ime\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
mRun: [PHIME2002ASync] c:\windows\system32\ime\tintlgnt\TINTSETP.EXE /SYNC
mRun: [PHIME2002A] c:\windows\system32\ime\tintlgnt\TINTSETP.EXE /IMEName
mRun: [ShStatEXE] "d:\program files\mcafee\virusscan enterprise\SHSTAT.EXE" /STANDALONE
mRun: [McAfeeUpdaterUI] "d:\program files\mcafee\common framework\UdaterUI.exe" /StartedFromRunKey
mRun: [SmartGuardian] d:\program files\ite\smart guardian\ITESMART.exe
mRun: [StartCCC] "d:\program files\ati technologies\ati.ace\core-static\CLIStart.exe" MSRun
mRun: [CTHelper] CTHELPER.EXE
mRun: [CTDVDDET] "d:\program files\creative\dvdaudio\CTDVDDET.EXE"
mRun: [RivaTunerStartupDaemon] "d:\program files\rivatuner v2.24\RivaTuner.exe" /S
dRunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N
StartupFolder: c:\docume~1\akaiki~1\startm~1\programs\startup\rivatu~1.lnk - d:\program files\rivatuner v2.24\RivaTuner.exe
uPolicies-explorer: ForceClassicControlPanel = 1 (0x1)
uPolicies-explorer: NoSMMyDocs = 1 (0x1)
uPolicies-explorer: NoSMMyPictures = 1 (0x1)
uPolicies-explorer: NoSMHelp = 1 (0x1)
uPolicies-explorer: NoSMConfigurePrograms = 1 (0x1)
mPolicies-system: DisableCAD = 1 (0x1)
dPolicies-explorer: ForceClassicControlPanel = 1 (0x1)
dPolicies-explorer: NoSMMyDocs = 1 (0x1)
dPolicies-explorer: NoSMMyPictures = 1 (0x1)
dPolicies-explorer: NoSMHelp = 1 (0x1)
dPolicies-explorer: NoSMConfigurePrograms = 1 (0x1)
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
DPF: {6C269571-C6D7-4818-BCA4-32A035E8C884} - hxxp://ccfiles.creative.com/Web/softwareupdate/su/ocx/15101/CTSUEng.cab
DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} - hxxp://ccfiles.creative.com/Web/softwareupdate/su/ocx/15110/CTPID.cab
Notify: AtiExtEvent - Ati2evxx.dll
Hosts: 127.0.0.1 www.spywareinfo.com
================= FIREFOX ===================
FF - ProfilePath - c:\docume~1\akaiki~1\applic~1\mozilla\firefox\profiles\s3atc122.default\
FF - prefs.js: browser.startup.homepage - www.google.com
FF - plugin: c:\documents and settings\akaikishi\application data\mozilla\firefox\profiles\s3atc122.default\extensions\iaplayer@instantaction.com\plugins\npiaplayer.dll
FF - plugin: c:\program files\windows media player\npdrmv2.dll
FF - plugin: c:\program files\windows media player\npdsplay.dll
FF - plugin: c:\program files\windows media player\npwmsdrm.dll
---- FIREFOX POLICIES ----
d:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
============= SERVICES / DRIVERS ===============
R2 McAfeeFramework;McAfee Framework Service;d:\program files\mcafee\common framework\FrameworkService.exe [2009-12-7 104000]
R2 McShield;McAfee McShield;d:\program files\mcafee\virusscan enterprise\mcshield.exe [2009-1-27 144704]
R2 McTaskManager;McAfee Task Manager;d:\program files\mcafee\virusscan enterprise\vstskmgr.exe [2009-1-27 54608]
R3 COMMONFX.SYS;COMMONFX.SYS;c:\windows\system32\drivers\COMMONFX.sys [2009-12-7 99416]
R3 CTAUDFX.SYS;CTAUDFX.SYS;c:\windows\system32\drivers\CTAUDFX.sys [2009-12-7 555096]
R3 ctgame;Game Port;c:\windows\system32\drivers\ctgame.sys [2009-12-7 18904]
R3 CTSBLFX.SYS;CTSBLFX.SYS;c:\windows\system32\drivers\CTSBLFX.sys [2009-12-7 566360]
R3 mfeavfk;McAfee Inc.;c:\windows\system32\drivers\mfeavfk.sys [2009-12-7 73512]
R3 mfebopk;McAfee Inc.;c:\windows\system32\drivers\mfebopk.sys [2009-12-7 34408]
R3 mfehidk;McAfee Inc.;c:\windows\system32\drivers\mfehidk.sys [2009-12-7 177864]
S3 COMMONFX;COMMONFX;c:\windows\system32\drivers\COMMONFX.sys [2009-12-7 99416]
S3 Creative Dolby Digital Live Pack Licensing Service;Creative Dolby Digital Live Pack Licensing Service;c:\program files\common files\creative labs shared\service\DDLLicensing.exe [2009-12-7 79360]
S3 CTAUDFX;CTAUDFX;c:\windows\system32\drivers\CTAUDFX.sys [2009-12-7 555096]
S3 CTERFXFX.SYS;CTERFXFX.SYS;c:\windows\system32\drivers\CTERFXFX.sys [2009-12-7 100952]
S3 CTERFXFX;CTERFXFX;c:\windows\system32\drivers\CTERFXFX.sys [2009-12-7 100952]
S3 CTSBLFX;CTSBLFX;c:\windows\system32\drivers\CTSBLFX.sys [2009-12-7 566360]
=============== Created Last 30 ================
2009-12-08 03:10:54 1080 ----a-w- c:\windows\system32\settingsbkup.sfm
2009-12-08 03:10:54 1080 ----a-w- c:\windows\system32\settings.sfm
2009-12-08 03:02:50 0 d-----w- c:\docume~1\akaiki~1\applic~1\GarageGames
2009-12-08 02:42:09 0 d-----w- d:\program files\RivaTuner v2.24
2009-12-08 02:19:12 218624 ----a-w- c:\windows\system32\uxtheme.uxtender
2009-12-08 02:06:59 7062 ----a-w- c:\windows\system32\audiopid.vxd
2009-12-08 01:42:36 33552 ----a-w- c:\windows\system32\BMXCtrlState-{00000005-00000000-00000002-00001102-00000004-20021102}.rfx
2009-12-08 01:42:36 33552 ----a-w- c:\windows\system32\BMXBkpCtrlState-{00000005-00000000-00000002-00001102-00000004-20021102}.rfx
2009-12-08 01:42:36 32976 ----a-w- c:\windows\system32\BMXStateBkp-{00000005-00000000-00000002-00001102-00000004-20021102}.rfx
2009-12-08 01:42:36 32976 ----a-w- c:\windows\system32\BMXState-{00000005-00000000-00000002-00001102-00000004-20021102}.rfx
2009-12-08 01:42:36 11564 ----a-w- c:\windows\system32\DVCState-{00000005-00000000-00000002-00001102-00000004-20021102}.rfx
2009-12-08 01:42:27 4932846 ------w- c:\windows\{00000005-00000000-00000002-00001102-00000004-20021102}.BAK
2009-12-08 01:39:44 0 d-----w- c:\program files\common files\Creative Labs Shared
2009-12-08 01:39:37 61440 ------w- c:\windows\system32\CTChkAud.dll
2009-12-08 01:39:37 6010 ------w- c:\windows\system32\CTOPT352.cat
2009-12-08 01:39:37 171680 ------w- c:\windows\system32\CTOPT352.dll
2009-12-08 01:37:29 65536 ------w- c:\windows\system32\ctdvda32.dll
2009-12-08 01:37:29 1746360 ------w- c:\windows\system32\CTAA1.DAT
2009-12-08 01:31:47 7572224 ------w- c:\windows\system32\CT8MGM.SF2
2009-12-08 01:31:47 4174814 ------w- c:\windows\system32\CT4MGM.SF2
2009-12-08 01:31:47 0 d-----w- c:\windows\system32\Defaults
2009-12-08 01:31:14 4932846 ----a-w- c:\windows\{00000005-00000000-00000002-00001102-00000004-20021102}.CDF
2009-12-08 01:31:07 444952 ----a-w- c:\windows\system32\wrap_oal.dll
2009-12-08 01:31:07 109080 ----a-w- c:\windows\system32\OpenAL32.dll
2009-12-08 01:30:46 0 d-----w- d:\program files\Creative
2009-12-08 01:30:46 0 d-----w- c:\windows\system32\Data
2009-12-08 01:28:35 6400 -c--a-w- c:\windows\system32\dllcache\enum1394.sys
2009-12-08 01:28:35 6400 ----a-w- c:\windows\system32\drivers\enum1394.sys
2009-12-08 01:28:20 61696 -c--a-w- c:\windows\system32\dllcache\ohci1394.sys
2009-12-08 01:28:20 61696 ----a-w- c:\windows\system32\drivers\ohci1394.sys
2009-12-08 01:28:19 53376 -c--a-w- c:\windows\system32\dllcache\1394bus.sys
2009-12-08 01:28:19 53376 ----a-w- c:\windows\system32\drivers\1394bus.sys
2009-12-08 01:14:56 60800 -c--a-w- c:\windows\system32\dllcache\sysaudio.sys
2009-12-08 00:30:17 189528 ----a-w- c:\windows\system32\drivers\haP17v2k.sys
2009-12-07 22:46:36 0 d-----w- d:\program files\Spybot - Search & Destroy
2009-12-07 22:46:36 0 d-----w- c:\docume~1\alluse~1\applic~1\Spybot - Search & Destroy
2009-12-07 18:34:00 887724 ----a-w- c:\windows\system32\ativva6x.dat
2009-12-07 18:34:00 7167 ----a-w- c:\windows\system32\atifglpf.xml
2009-12-07 18:34:00 479232 ----a-w- c:\windows\system32\ATIDEMGX.dll
2009-12-07 18:33:59 18618 ----a-w- c:\windows\atiogl.xml
2009-12-07 18:33:58 311296 ----a-w- c:\windows\system32\atiiiexx.dll
2009-12-07 18:33:58 3 ----a-w- c:\windows\system32\ativva5x.dat
2009-12-07 18:33:58 195855 ----a-w- c:\windows\system32\atiicdxx.dat
2009-12-07 18:33:33 0 d-----w- d:\program files\ATI Technologies
2009-12-07 18:29:29 0 d-sh--w- c:\documents and settings\akaikishi\PrivacIE
2009-12-07 18:26:49 0 d-sh--w- c:\documents and settings\akaikishi\IETldCache
2009-12-07 18:24:53 0 d-----w- c:\windows\ie8updates
2009-12-07 18:24:50 594432 -c----w- c:\windows\system32\dllcache\msfeeds.dll
2009-12-07 18:24:50 55296 -c----w- c:\windows\system32\dllcache\msfeedsbs.dll
2009-12-07 18:24:50 246272 -c----w- c:\windows\system32\dllcache\ieproxy.dll
2009-12-07 18:24:50 1985536 -c----w- c:\windows\system32\dllcache\iertutil.dll
2009-12-07 18:24:50 12800 -c----w- c:\windows\system32\dllcache\xpshims.dll
2009-12-07 18:24:50 11069440 -c----w- c:\windows\system32\dllcache\ieframe.dll
2009-12-07 18:23:57 0 dc-h--w- c:\windows\ie8
2009-12-07 12:15:14 272128 -c----w- c:\windows\system32\dllcache\bthport.sys
2009-12-07 12:15:14 272128 ------w- c:\windows\system32\drivers\bthport.sys
2009-12-07 12:02:23 455296 -c----w- c:\windows\system32\dllcache\mrxsmb.sys
2009-12-07 11:59:25 0 d-----w- d:\program files\Seagate
2009-12-07 11:59:17 2145280 -c----w- c:\windows\system32\dllcache\ntkrnlmp.exe
2009-12-07 11:59:17 2023936 -c----w- c:\windows\system32\dllcache\ntkrpamp.exe
2009-12-07 11:59:16 2066048 -c----w- c:\windows\system32\dllcache\ntkrnlpa.exe
2009-12-07 11:57:05 0 d-sh--w- c:\documents and settings\akaikishi\UserData
2009-12-07 11:56:06 0 d-----w- d:\program files\ATI
2009-12-07 11:55:52 14048 ------w- c:\windows\system32\spmsg2.dll
2009-12-07 11:54:50 0 d-----w- c:\windows\system32\PreInstall
2009-12-07 11:54:49 26144 ----a-w- c:\windows\system32\spupdsvc.exe
2009-12-07 11:54:48 0 d--h--w- c:\windows\$hf_mig$
2009-12-07 11:54:35 0 d-----w- C:\ATI
2009-12-07 11:50:51 0 d-----w- c:\windows\system32\SoftwareDistribution
2009-12-07 11:45:46 280 ----a-w- c:\windows\system32\epoPGPsdk.dll.sig
2009-12-07 11:45:33 73512 ----a-w- c:\windows\system32\drivers\mfeavfk.sys
2009-12-07 11:45:33 65000 ----a-w- c:\windows\system32\drivers\mfeapfk.sys
2009-12-07 11:45:33 52168 ----a-w- c:\windows\system32\drivers\mfetdik.sys
2009-12-07 11:45:33 34408 ----a-w- c:\windows\system32\drivers\mfebopk.sys
2009-12-07 11:45:33 177864 ----a-w- c:\windows\system32\drivers\mfehidk.sys
2009-12-07 11:45:28 0 d-----w- d:\program files\McAfee
2009-12-07 11:45:28 0 d-----w- c:\program files\common files\McAfee
2009-12-07 11:43:03 0 d-----w- c:\windows\system32\appmgmt
2009-12-07 11:39:44 499712 ----a-w- c:\windows\system32\msvcp71.dll
2009-12-07 11:39:44 348160 ----a-w- c:\windows\system32\msvcr71.dll
2009-12-07 11:39:44 1495552 ----a-w- c:\windows\system32\epoPGPsdk.dll
2009-12-07 11:39:44 0 d-----w- c:\program files\common files\Cisco Systems
2009-12-07 11:34:08 0 d-----w- d:\program files\windows nt
2009-12-07 11:34:08 0 d-----w- d:\program files\msn gaming zone
2009-12-07 11:33:12 0 d-----w- c:\program files\common files\Wise Installation Wizard
2009-12-07 11:32:57 118784 ----a-r- c:\windows\system32\Msstdfmt.dll
2009-12-07 11:32:57 1066176 ----a-w- c:\windows\system32\Mscomctl.ocx
2009-12-07 11:32:56 6080 ----a-w- c:\windows\system32\drivers\zntport.sys
2009-12-07 11:32:56 46080 ----a-r- c:\windows\system32\itevio.dll
2009-12-07 11:32:56 112 ----a-w- c:\windows\system32\drivers\a.bat
2009-12-07 11:32:56 102912 ----a-r- c:\windows\system32\Ntport.dll
2009-12-07 11:32:56 0 d-----w- d:\program files\ITE
2009-12-07 11:32:56 0 d-----w- c:\windows\SysWow64
2009-12-07 11:32:19 0 d-----w- d:\program files\Marvell
2009-12-07 11:32:11 0 d-----w- c:\program files\common files\InstallShield
2009-12-07 11:30:47 0 d-----w- c:\windows\system32\ReinstallBackups
2009-12-07 11:30:27 0 d-----w- C:\Intel
2009-12-07 11:16:57 0 d-----w- c:\windows\system32\NtmsData
2009-12-07 05:24:24 0 d-sh--w- c:\documents and settings\all users\DRM
2009-12-07 05:23:46 0 d-----w- c:\program files\common files\MSSoap
2009-12-07 00:18:10 0 d-----w- c:\program files\common files\ODBC
2009-12-07 00:18:08 0 d-----w- c:\program files\common files\SpeechEngines
2009-12-07 00:16:54 0 d-----r- c:\documents and settings\all users\Documents
==================== Find3M ====================
2009-12-08 02:19:12 218624 ----a-w- c:\windows\system32\uxtheme.dll
2009-12-07 05:22:59 21640 ----a-w- c:\windows\system32\emptyregdb.dat
2009-11-04 16:15:30 4423168 ----a-w- c:\windows\system32\drivers\ati2mtag.sys
2009-11-04 15:44:14 300032 ----a-w- c:\windows\system32\ati2dvag.dll
2009-11-04 15:29:44 204800 ----a-w- c:\windows\system32\atipdlxx.dll
2009-11-04 15:29:28 155648 ----a-w- c:\windows\system32\Oemdspif.dll
2009-11-04 15:29:16 26112 ----a-w- c:\windows\system32\Ati2mdxx.exe
2009-11-04 15:29:08 43520 ----a-w- c:\windows\system32\ati2edxx.dll
2009-11-04 15:28:54 155648 ----a-w- c:\windows\system32\ati2evxx.dll
2009-11-04 15:27:40 602112 ----a-w- c:\windows\system32\ati2evxx.exe
2009-11-04 15:26:18 53248 ----a-w- c:\windows\system32\ATIDDC.DLL
2009-11-04 15:18:50 3518304 ----a-w- c:\windows\system32\ati3duag.dll
2009-11-04 15:17:48 13000704 ----a-w- c:\windows\system32\atioglxx.dll
2009-11-04 15:05:10 2135680 ----a-w- c:\windows\system32\ativvaxx.dll
2009-11-04 14:51:08 65024 ----a-w- c:\windows\system32\atimpc32.dll
2009-11-04 14:51:08 65024 ----a-w- c:\windows\system32\amdpcom32.dll
2009-11-04 14:47:16 565248 ----a-w- c:\windows\system32\atikvmag.dll
2009-11-04 14:46:58 45056 ----a-w- c:\windows\system32\aticalrt.dll
2009-11-04 14:46:44 45056 ----a-w- c:\windows\system32\aticalcl.dll
2009-11-04 14:45:30 172032 ----a-w- c:\windows\system32\atiadlxx.dll
2009-11-04 14:45:08 3526656 ----a-w- c:\windows\system32\aticaldd.dll
2009-11-04 14:45:04 17408 ----a-w- c:\windows\system32\atitvo32.dll
2009-11-04 14:44:48 397312 ----a-w- c:\windows\system32\atiok3x2.dll
2009-11-04 14:44:20 53248 ----a-w- c:\windows\system32\drivers\ati2erec.dll
2009-11-04 14:39:26 638976 ----a-w- c:\windows\system32\ati2cqag.dll
2009-10-02 21:19:30 623962 ----a-w- c:\windows\system32\UDAAIM32.exe
2009-09-23 21:19:34 43520 ----a-w- c:\windows\system32\CTBurst.dll
2009-09-23 21:19:16 11776 ----a-w- c:\windows\system32\inres.dll
2009-09-23 21:19:16 11776 ----a-w- c:\windows\INRES.DLL
2009-09-23 21:19:12 86528 ----a-w- c:\windows\system32\ctcoinst.dll
2009-09-23 21:19:12 182272 ----a-w- c:\windows\system32\ctdvinst.dll
2009-09-23 21:18:08 10752 ----a-w- c:\windows\system32\a3d.dll
2009-09-23 21:06:36 51787 ----a-w- c:\windows\system32\ctdlang.dat
2009-09-23 21:06:36 386852 ----a-w- c:\windows\system32\ctdnlstr.dat
2009-09-23 21:06:00 196096 ----a-w- c:\windows\system32\ctemupia.dll
2009-09-23 21:03:28 176128 ----a-w- c:\windows\system32\ct_oal.dll
2009-09-23 21:03:26 46592 ----a-w- c:\windows\system32\ctasio.dll
2009-09-23 21:03:22 49152 ----a-w- c:\windows\system32\ctdproxy.dll
2009-09-23 21:03:04 69632 ----a-w- c:\windows\system32\ctosuser.dll
2009-09-23 21:03:02 6144 ----a-w- c:\windows\system32\sfman32.dll
2009-09-23 21:02:58 125952 ----a-w- c:\windows\system32\sfms32.dll
2009-09-23 21:02:54 13312 ----a-w- c:\windows\system32\regplib.exe
2009-09-23 21:02:52 64512 ----a-w- c:\windows\system32\piaproxy.dll
2009-09-23 21:01:54 149838 ----a-w- c:\windows\system32\ctbas2w.dat
2009-09-23 21:00:24 274587 ----a-w- c:\windows\system32\ctsbas2w.dat
2009-09-23 20:59:38 53932 ----a-w- c:\windows\system32\ctdaught.dat
2009-09-23 20:59:36 313207 ----a-w- c:\windows\system32\ctstatic.dat
2009-09-23 20:59:34 5120 ----a-w- c:\windows\system32\enlocstr.exe
2009-09-23 20:59:30 10240 ----a-w- c:\windows\system32\killapps.exe
2009-09-23 20:59:10 28672 ----a-w- c:\windows\system32\MIDIDEF.EXE
2009-09-23 20:59:08 33792 ----a-w- c:\windows\system32\devreg.dll
2009-09-11 14:18:39 136192 ----a-w- c:\windows\system32\msv1_0.dll
============= FINISH: 23:43:53.56 ===============
Attached File(s)
-
Attach.txt (6.69K)
Number of downloads: 0 -
ark.txt (860bytes)
Number of downloads: 1 -
hijackthis.log (5.18K)
Number of downloads: 1

Help
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.
This topic is locked

Back to top










