I have this computer for about 5-6 years and till now, everything worked good. I have Windows XP and it is installed 5-6 years ago. Few days ago, when I put my USB flash in, some files automatically get copied on USB. I scaned it at my new computer and Kaspersky cleaned about 70 sality viruses. Can you help me, i read instructions 3 times
I tried running DDS, and nothing happens when I double-click it. I tried few times, and nothing happens. I also restarted computer and it's still now working
I was able only to attach Gmer log...
UPDATE: From tonight my computer working even slower, I can't even play music normally, it lagging, when i switch to another program or folder...
I searched your forum, and downloaded DDS.com, and now I was able to produce logs
Here is the DDS log:
.
DDS (Ver_2011-06-23.01) - NTFSx86
Internet Explorer: 7.0.5730.13
Run by DJORDJE at 10:47:44 on 2011-07-13
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.255.26 [GMT 2:00]
.
AV: Microsoft Security Essentials *Enabled/Outdated* {EDB4FA23-53B8-4AFA-8C5D-99752CCA7095}
.
============== Running Processes ===============
.
C:\WINDOWS\system32\svchost.exe -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Win\lsass.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\wscntfy.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.google.rs/
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uInternet Connection Wizard,ShellNext = iexplore
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
uURLSearchHooks: Winamp Search Class: {57bca5fa-5dbb-45a2-b558-1755c3f6253b} - c:\program files\winamp toolbar\winamptb.dll
mURLSearchHooks: Winamp Search Class: {57bca5fa-5dbb-45a2-b558-1755c3f6253b} - c:\program files\winamp toolbar\winamptb.dll
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Winamp Toolbar Loader: {25cee8ec-5730-41bc-8b58-22ddc8ab8c20} - c:\program files\winamp toolbar\winamptb.dll
BHO: NOW!Imaging: {9aa2f14f-e956-44b8-8694-a5b615cdf341} - c:\program files\raketa krstarice\components\NOWImaging.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.4.4525.1752\swg.dll
TB: {E0E899AB-F487-11D5-8D29-0050BA6940E3} - No File
TB: Winamp Toolbar: {ebf2ba02-9094-4c5a-858b-bb198f3d8de2} - c:\program files\winamp toolbar\winamptb.dll
TB: BS.Player ControlBar: {2c688203-7eb3-4327-9995-1cb417ba23f9} - c:\program files\bs.player controlbar\BSToolbar.dll
TB: {8B79EE88-E62D-4AA8-B530-CC357BA112B7} - No File
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
mRun: [SoundMan] SOUNDMAN.EXE
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [nwiz] nwiz.exe /install
mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit
mRun: [RemoteControl] "c:\program files\cyberlink\powerdvd\PDVDServ.exe"
mRun: [run32] c:\win\lsass.exe
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 10.0\reader\Reader_sl.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
dRun: [DWQueuedReporting] "c:\progra~1\common~1\micros~1\dw\dwtrig20.exe" -t
mPolicies-system: EnableLUA = 0 (0x0)
mPolicies-system: DisableStatusMessages = 1 (0x1)
mPolicies-system: LogonType = 0 (0x0)
IE: &Winamp Search - c:\documents and settings\all users\application data\winamp toolbar\ietoolbar\resources\en-us\local\search.html
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office10\EXCEL.EXE/3000
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
DPF: Microsoft XML Parser for Java - file://c:\windows\java\classes\xmldso.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab
TCP: Interfaces\{AA814A3C-F69B-43B9-91C3-205B9FFBCD73} : NameServer = 212.62.32.1 212.62.32.5
Handler: cdo - {CD00020A-8B95-11D1-82DB-00C04FB1625D} - c:\program files\common files\microsoft shared\web folders\PKMCDO.DLL
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\documents and settings\djordje\application data\mozilla\firefox\profiles\no895450.default\
FF - prefs.js: browser.startup.homepage - www.google.rs
FF - plugin: c:\program files\k-lite codec pack\real\browser\plugins\nppl3260.dll
FF - plugin: c:\program files\k-lite codec pack\real\browser\plugins\nprpjplug.dll
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Auto Hide IP: support@auto-hide-ip.com - %profile%\extensions\support@auto-hide-ip.com
.
============= SERVICES / DRIVERS ===============
.
R3 aic32p;aic32p;\??\c:\windows\system32\drivers\mskoji.sys --> c:\windows\system32\drivers\mskoji.sys [?]
S3 VirtualDK;VirtualDK;\??\c:\documents and settings\djordje\desktop\xp\usp prep8\usb_prep8\vdk.sys --> c:\documents and settings\djordje\desktop\xp\usp prep8\usb_prep8\vdk.sys [?]
.
=============== Created Last 30 ================
.
2011-06-27 18:20:42 -------- d-----w- c:\program files\NCBuy
.
==================== Find3M ====================
.
2011-06-05 09:06:26 404640 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-06-04 21:22:18 1626112 ----a-w- c:\windows\system32\nwiz.exe
2011-05-24 17:14:10 222080 ------w- c:\windows\system32\MpSigStub.exe
2009-12-27 15:44:02 84992 --sh--r- c:\windows\system32\ckvo4.dll
.
============= FINISH: 10:49:09.98 ===============
UPDATE:
I also scanned with MalwareByte's Anti Malware, and it shows 7 malicious objects. Worm AutoIT
Here is the log:
Malwarebytes' Anti-Malware 1.51.0.1200
www.malwarebytes.org
Database version: 6705
Windows 5.1.2600 Service Pack 3, v.3264
Internet Explorer 7.0.5730.13
7/13/2011 7:07:04 PM
mbam-log-2011-07-13 (19-06-51).txt
Scan type: Full scan (C:\|F:\|)
Objects scanned: 199523
Time elapsed: 1 hour(s), 38 minute(s), 1 second(s)
Memory Processes Infected: 1
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 1
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 5
Memory Processes Infected:
c:\Win\lsass.exe (Worm.AutoIT) -> 300 -> No action taken.
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\run32 (Worm.AutoIT) -> Value: run32 -> No action taken.
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
c:\83fgj.com (Spyware.OnlineGames.PS) -> No action taken.
c:\WINDOWS\system32\ckvo4.dll (Spyware.OnlineGames) -> No action taken.
f:\83fgj.com (Spyware.OnlineGames.PS) -> No action taken.
c:\Win\lsass.exe (Worm.AutoIT) -> No action taken.
c:\Win\names.txt (Worm.AutoIT) -> No action taken.
I did nothing, and waiting for further instuctions...
EDIT: Posts merged ~Budapest
Can you tell me, how much time I still need to wait for response, because I really need this computer fixed. I had to transfer some data to another hard disk, and I don't wanna infect other hard disk! I can wait, it's not problem, I just need to know for how much...
EDIT: The current average wait time to receive help is 14 days. ~Budapest
Attached File(s)
-
attach.txt (3.81K)
Number of downloads: 0 -
ark.txt (916bytes)
Number of downloads: 3
This post has been edited by Budapest: 18 July 2011 - 04:59 PM

Help
This topic is locked


Back to top










