Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Infected with brask and internet speed monitor


  • This topic is locked This topic is locked
10 replies to this topic

#1 megaxz8642

megaxz8642

  • Members
  • 11 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:02:41 PM

Posted 04 January 2009 - 01:20 AM

Hello,

The computer that is infected right now is my father's computer but I will refer to it as my own. I believe that my computer is heavily infected with viruses like brastk. I was previously getting a red circle with a red X on it with a pop up stating I was heavily infected. I rid of them by preventing the startup of brastk. I am also getting popups that say they are from internet speed monitor. The computer is now running incredibly slow. Any help is appreciated.

Here is my DDS log:

DDS (Version 1.1.0) - NTFSx86
Run by Joseph M Gopez Sr at 21:29:51.13 on Sat 01/03/2009
Internet Explorer: 7.0.5730.11
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.510.287 [GMT -8:00]

AV: AVG Anti-Virus *On-access scanning enabled* (Outdated)

============== Running Processes ===============

C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Common Files\Dell\EUSW\Support.exe
C:\Program Files\Alpha Networks\ANIWZCS Service\WZCSLDR.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Dell\Media Experience\PCMService.exe
C:\Program Files\D-Link\Air Utility\AirCFG.exe
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
C:\Program Files\Dell\Support\Alert\bin\NotifyAlert.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Network World iDemand\Network World iDemand.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\System32\svchost.exe -k imgsvc
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\GetModule\GetModule31.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\WINDOWS\system32\rundll32.exe
C:\DOCUME~1\JOSEPH~1\LOCALS~1\Temp\stf21.tmp
C:\Program Files\Internet Explorer\iexplore.exe
C:\PROGRA~1\JavaSoft\JRE1.4\14267D~1.1\bin\javaw.exe
C:\Documents and Settings\Joseph M Gopez Sr\Application Data\Microsoft\Windows\urwilh.exe
C:\Documents and Settings\Joseph M Gopez Sr\Application Data\SpeedRunner\SpeedRunner.exe
C:\Documents and Settings\Joseph M Gopez Sr\Desktop\dds.scr

============== Pseudo HJT Report ===============

uStart Page = hxxp://www.google.com
uSearch Page = hxxp://www.google.com
uSearch Bar = hxxp://www.google.com/ie
mDefault_Search_URL = hxxp://www.google.com/ie
mSearch Page = hxxp://www.google.com
mStart Page = hxxp://www.google.com
uSearchAssistant = hxxp://www.google.com
mSearchAssistant = hxxp://www.google.com
mWinlogon: Userinit=userinit.exe
mWinlogon: SFCDisable=-99 (0xffffff9d)
BHO: BHO Class: {15421b84-3488-49a7-ad18-cbf84a3efaf6} - c:\program files\webtools\webtools.dll
BHO: {3B0CD1C6-9CDE-41A2-8644-5C3AEFA9DBDC} - No File
BHO: {628B117B-0106-4443-B6C3-94311ED1117B} - No File
BHO: Java™ Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre6\bin\ssv.dll
BHO: {88EC2661-35AB-4E94-AC07-74686E9CE0A5} - No File
BHO: {a80d91c6-806a-4005-a153-be9c9e599f9b} - c:\windows\system32\yayvUklJ.dll
BHO: {BF950D8D-8A2A-491F-8CE6-E94E5DA9607F} - No File
BHO: Mjcore Class: {d88e1558-7c2d-407a-953a-c044f5607cea} - c:\program files\mjcore\Mjcore.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn2\yt.dll
EB: &Yahoo! Messenger: {4528bbe0-4e08-11d5-ad55-00010333d0ad} - c:\progra~1\yahoo!\common\yhexbmesus.dll
EB: Real.com: {fe54fa40-d68c-11d2-98fa-00c0f0318afe} - c:\windows\system32\Shdocvw.dll
EB: {32683183-48a0-441b-a342-7c2a440a9478} - No File
EB: SpeedRunner Bar: {cafb2180-ba09-11dc-95ff-0800200c9a66} - %SystemRoot%\system32\shdocvw.dll
uRun: [ForbesInvesting] c:\program files\forbesinvesting\ForbesInvestingAlerts.exe
uRun: [Network World iDemand] "c:\program files\network world idemand\Network World iDemand.exe" -r
uRun: [xrt_Shell] c:\documents and settings\joseph m gopez sr\xrt_iqyd.exe
uRun: [ApiAdm] c:\windows\system32\oxexkziz.exe
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [updateMgr] c:\program files\adobe\acrobat 7.0\reader\AdobeUpdateManager.exe AcRdB7_0_5 -reboot 1
uRun: [SpybotSD TeaTimer] c:\program files\spybot - search & destroy\TeaTimer.exe
uRun: [Skype] "c:\program files\skype\phone\Skype.exe" /nosplash /minimized
uRun: [GetModule31] c:\program files\getmodule\GetModule31.exe
uRun: [GetModule32] "c:\program files\getmodule\GetModule32.exe"
uRun: [gadcom] "c:\documents and settings\joseph m gopez sr\application data\gadcom\gadcom.exe" 61A847B5BBF72815308B2B27128065E9C084320161C4661227A755E9C2933154389A
uRun: [SpeedRunner] c:\documents and settings\joseph m gopez sr\application data\speedrunner\SpeedRunner.exe
uRun: [SfKg6wIP] c:\documents and settings\joseph m gopez sr\application data\microsoft\windows\urwilh.exe
uRunOnce: [FlashPlayerUpdate] c:\windows\system32\macromed\flash\FlashUtil9e.exe
mRun: [IgfxTray] c:\windows\system32\igfxtray.exe
mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe
mRun: [TkBellExe] "c:\program files\common files\real\update_ob\realsched.exe" -osboot
mRun: [DwlClient] c:\program files\common files\dell\eusw\Support.exe
mRun: [NT Logging Service] syslog32.exe
mRun: [ANIWZCSService] c:\program files\alpha networks\aniwzcs service\WZCSLDR.exe
mRun: [IMJPMIG8.1] "c:\windows\ime\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [nwiz] nwiz.exe /install
mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit
mRun: [HP Software Update] c:\program files\hp\hp software update\HPWuSchd2.exe
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [PCMService] "c:\program files\dell\media experience\PCMService.exe"
mRun: [D-Link Air Utility] c:\program files\d-link\air utility\AirCFG.exe
mRun: [brastk] brastk.exe
mRun: [Adobe Photo Downloader] "c:\program files\adobe\photoshop album starter edition\3.0\apps\apdproxy.exe"
mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
mRunServices: [Audoi Device Loader] smssv.exe
mRunServices: [Microsoft System Checkup] libsysmgr.exe
StartupFolder: c:\documents and settings\joseph m gopez sr\start menu\programs\startup\PowerReg Scheduler.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\digita~1.lnk - c:\program files\digital line detect\DLG.exe
IE: &Yahoo! Search - file:///c:\program files\yahoo!\Common/ycsrch.htm
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office10\EXCEL.EXE/3000
IE: Yahoo! &Dictionary - file:///c:\program files\yahoo!\Common/ycdict.htm
IE: Yahoo! &Maps - file:///c:\program files\yahoo!\Common/ycmap.htm
IE: Yahoo! &SMS - file:///c:\program files\yahoo!\Common/ycsms.htm
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - c:\program files\yahoo!\common\yiesrvc.dll
IE: {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - {FE54FA40-D68C-11d2-98FA-00C0F0318AFE} - c:\windows\system32\Shdocvw.dll
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\program files\spybot - search & destroy\SDHelper.dll
Trusted Zone: rjobrien.com\vandemo
Trusted Zone: rjobrien.com\vanweb
Handler: cdo - {CD00020A-8B95-11D1-82DB-00C04FB1625D} - c:\program files\common files\microsoft shared\web folders\PKMCDO.DLL
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} -
Notify: awtsPHxx - awtsPHxx.dll
Notify: hgGxWmnO - hgGxWmnO.dll
Notify: igfxcui - igfxsrvc.dll
Notify: __c00CE5A0 - c:\windows\system32\__c00CE5A0.dat
AppInit_DLLs: karna.dat pxfgen.dll bmmmxi.dll
SSODL: setinfo - {618685D1-4E5A-F8ED-18F2-01B95CF4F502} - c:\program files\guhaqdc\setinfo.dll
SEH: {6d794cb4-c7cd-4c6f-bfdc-9b77afbdc02c} - c:\windows\system32\hgGxWmnO.dll
SecurityProviders: msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll, digeste.dll
LSA: Authentication Packages = msv1_0 c:\windows\system32\yayvUklJ

============= SERVICES / DRIVERS ===============


=============== Created Last 30 ================

2009-01-03 21:26 <DIR> --d----- c:\docume~1\joseph~1\applic~1\SpeedRunner
2009-01-03 21:16 <DIR> --d----- c:\program files\Webtools
2009-01-03 21:11 <DIR> --d----- c:\program files\Mjcore
2009-01-03 21:11 <DIR> --d----- c:\docume~1\joseph~1\applic~1\gadcom
2009-01-03 21:10 34,816 a------- c:\windows\system32\hgGxWmnO.dll
2009-01-03 21:10 <DIR> --d----- c:\program files\iCheck
2009-01-03 21:10 198,716 a------- c:\windows\system32\wpv911229907513.cpx
2009-01-03 21:10 22,016 a------- c:\windows\system32\digeste.dll
2009-01-03 21:07 129,024 a------- c:\windows\system32\bmmmxi.dll
2009-01-03 21:07 129,024 a------- c:\windows\system32\hegoyuky.dll
2009-01-03 21:07 1,755,812 ---sh--- c:\windows\system32\geuohxir.ini
2009-01-03 21:07 72,704 a------- c:\windows\system32\rixhoueg.dll
2009-01-03 21:07 102,176 a------- c:\windows\system32\cont_globaladsolution-remove.exe
2009-01-03 21:07 47,593 a------- c:\windows\system32\flokawkumnjn.exe
2008-12-23 12:16 410,984 a------- c:\windows\system32\deploytk.dll
2008-12-23 12:16 73,728 a------- c:\windows\system32\javacpl.cpl
2008-12-23 11:54 1,755,812 ---sh--- c:\windows\system32\lnoxbdrg.ini
2008-12-23 11:54 72,704 -------- c:\windows\system32\grdbxonl.dll
2008-12-23 11:51 129,024 a------- c:\windows\system32\xhedsz.dll
2008-12-23 11:51 129,024 a------- c:\windows\system32\rwwuctds.dll
2008-12-21 12:20 129,024 a------- c:\windows\system32\aiwphn.dll
2008-12-21 12:20 129,024 a------- c:\windows\system32\qsyigwrc.dll
2008-12-21 12:16 1,661,209 ---sh--- c:\windows\system32\pcfsaceq.ini
2008-12-11 16:05 1,623,552 ---sh--- c:\windows\system32\ylqtbsun.ini
2008-12-11 16:05 72,704 a------- c:\windows\system32\nusbtqly.dll
2008-12-11 16:03 129,024 a------- c:\windows\system32\pxfgen.dll
2008-12-11 16:03 129,024 a------- c:\windows\system32\rmuwylxl.dll
2008-12-10 13:33 <DIR> --d----- c:\windows\LMI9B.tmp
2008-12-06 12:10 1,479,831 a--sh--- c:\windows\system32\ymoovdvd.ini
2008-12-06 12:10 72,704 a------- c:\windows\system32\dvdvoomy.dll
2008-12-06 12:09 715,488 a--sh--- c:\windows\system32\JlkUvyay.ini2
2008-12-06 12:09 715,488 a--sh--- c:\windows\system32\JlkUvyay.ini
2008-12-06 12:09 302,592 a------- c:\windows\system32\yayvUklJ.dll
2008-12-06 12:04 65,024 a------- c:\windows\system32\yayvWqoM.dll
2008-12-06 12:04 <DIR> --d----- c:\docume~1\joseph~1\applic~1\GetModule
2008-12-06 12:04 198,710 a------- c:\windows\system32\wpv671228549770.cpx
2008-12-06 12:04 <DIR> --d----- c:\program files\GetModule

==================== Find3M ====================

2008-12-23 20:20 389,632 a------- c:\windows\system32\jkuishwibyksqswgr.dll
2008-12-06 12:27 638 a------- c:\documents and settings\joseph m gopez sr\xrt_log.dat
2008-12-03 04:22 370,176 a------- c:\windows\system32\_jkuishwibyksqswgr.dll
2008-12-02 08:41 676,352 a------- c:\windows\system32\nst13.dll
2008-11-23 14:42 27,136 a------- c:\documents and settings\joseph m gopez sr\xrt_temp1.exe
2008-11-23 14:24 214 a------- C:\xcrashdump.dat
2008-11-07 17:52 93,115 a------- c:\windows\system32\wini104552502.exe
2008-11-06 22:55 24,064 a------- c:\windows\system32\__c0024D62.dat
2008-10-16 22:37 3,022 a------- c:\windows\system32\tmp.reg
2008-10-16 22:31 44,032 a------- c:\windows\system32\~.exe
2008-10-10 07:58 82,944 a------- c:\windows\system32\o4Patch.exe
2008-10-10 07:58 82,944 a------- c:\windows\system32\IEDFix.C.exe
2008-10-09 23:25 502,272 a------- c:\windows\system32\winlogon.exe
2008-10-09 23:25 295,424 a------- c:\windows\system32\termsrv.dll
2008-02-22 10:57 35,568 ac------ c:\docume~1\joseph~1\applic~1\GDIPFONTCACHEV1.DAT
2004-08-23 16:54 45,056 a------- c:\program files\Pivot Calculator1.1c.exe

============= FINISH: 21:35:20.47 ===============

Attached Files



BC AdBot (Login to Remove)

 


#2 fenzodahl512

fenzodahl512

  • Members
  • 6,738 posts
  • OFFLINE
  •  
  • Local time:06:41 AM

Posted 05 January 2009 - 02:51 AM

Please make sure you disable ALL of your Antivirus/Antispyware/Firewall before running ComboFix.. Please visit HERE if you don't know how.. Please re-enable them back after performing all steps given..

Please download ComboFix by sUBs from one of the locations below, and save it to your Desktop.

Link 1
Link 2
Link 3

Double click combofix.exe and follow the prompts. Please, never rename Combofix unless instructed.

If ComboFix asked you to install Recovery Console, please do so.. It will be your best interest..

When finished, it shall produce a log for you. Post that log and a fresh HijackThis log in your next reply..

Note: DO NOT mouseclick combofix's window while its running. That may cause it to stall

Keep calm, make it simple, use your brain, don't freak out, and you'll be just fine..
Awesomeness: When I get sad, I stop being sad and be awesome instead.. True story - Barney Stinson
Posted Image Posted Image
Its gonna be legen.. wait for it.. dary! Cherish the pain, it means you're still alive


#3 megaxz8642

megaxz8642
  • Topic Starter

  • Members
  • 11 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:02:41 PM

Posted 07 January 2009 - 05:20 PM

Hello, thanks for looking into my computer issues. I tried to run combofix after I had turned off all of my antivirus/firewall/spyware programs, but it said that AVG anti-virus was still running. While AVG8 appears in my program folder, it does not appear in my system tray. Should I run combofix anyway?

#4 fenzodahl512

fenzodahl512

  • Members
  • 6,738 posts
  • OFFLINE
  •  
  • Local time:06:41 AM

Posted 08 January 2009 - 01:19 AM

Yup.. Just run it :thumbsup:

Keep calm, make it simple, use your brain, don't freak out, and you'll be just fine..
Awesomeness: When I get sad, I stop being sad and be awesome instead.. True story - Barney Stinson
Posted Image Posted Image
Its gonna be legen.. wait for it.. dary! Cherish the pain, it means you're still alive


#5 megaxz8642

megaxz8642
  • Topic Starter

  • Members
  • 11 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:02:41 PM

Posted 09 January 2009 - 03:10 AM

I was able to run Combofix. I've already seen vast improvements! The popups are gone and the computer is running more to its usual speed. However, after a search result through google or yahoo, instead of going to the link I click on I am redirected to a random site.

Here is my Combofix log first:
ComboFix 09-01-08.03 - Joseph M Gopez Sr 2009-01-08 23:42:53.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.510.198 [GMT -8:00]
Running from: c:\documents and settings\Joseph M Gopez Sr\Desktop\ComboFix.exe
AV: AVG Anti-Virus *On-access scanning enabled* (Outdated)
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat
c:\documents and settings\Joseph M Gopez Sr\Application Data\gadcom
c:\documents and settings\Joseph M Gopez Sr\Application Data\gadcom\gadcom.exe
c:\documents and settings\Joseph M Gopez Sr\Application Data\GetModule
c:\documents and settings\Joseph M Gopez Sr\Application Data\GetModule\dicik.gz
c:\documents and settings\Joseph M Gopez Sr\Application Data\GetModule\kwdik.gz
c:\documents and settings\Joseph M Gopez Sr\Application Data\GetModule\ofadik.gz
c:\documents and settings\Joseph M Gopez Sr\Application Data\SpamBlockerUtility
c:\documents and settings\Joseph M Gopez Sr\Application Data\SpeedRunner
c:\documents and settings\Joseph M Gopez Sr\Application Data\SpeedRunner\config.cfg
c:\documents and settings\Joseph M Gopez Sr\Application Data\SpeedRunner\SpeedRunner.exe
c:\documents and settings\Joseph M Gopez Sr\Application Data\SpeedRunner\SRUninstall.exe
c:\documents and settings\Joseph M Gopez Sr\Local Settings\Temporary Internet Files\CPV.stt
c:\documents and settings\Joseph M Gopez Sr\Local Settings\Temporary Internet Files\fbk.sts
c:\program files\GetModule
c:\program files\GetModule\GetModule31.exe
c:\program files\GetModule\GetModule32.exe
c:\program files\iCheck
c:\program files\iCheck\Uninstall.exe
c:\program files\Mjcore
c:\program files\Mjcore\Mjcore.dll
c:\windows\system32\__c0024D62.dat
c:\windows\system32\__c003A22D.dat
c:\windows\system32\__c0070D6A.dat
c:\windows\system32\~.exe
c:\windows\system32\404Fix.exe
c:\windows\system32\aiwphn.dll
c:\windows\system32\bmmmxi.dll
c:\windows\system32\cont_globaladsolution-remove.exe
c:\windows\system32\digeste.dll
c:\windows\system32\drivers\fad.sys
c:\windows\system32\dumphive.exe
c:\windows\system32\dvdvoomy.dll
c:\windows\system32\geuohxir.ini
c:\windows\system32\hchkgbjk.ini
c:\windows\system32\hegoyuky.dll
c:\windows\system32\hgGxWmnO.dll
c:\windows\system32\IEDFix.C.exe
c:\windows\system32\IEDFix.exe
c:\windows\system32\jkuishwibyksqswgr.dll
c:\windows\system32\JlkUvyay.ini
c:\windows\system32\JlkUvyay.ini2
c:\windows\system32\kjbgkhch.dll
c:\windows\system32\korybfhr.dll
c:\windows\system32\lnoxbdrg.ini
c:\windows\system32\nusbtqly.dll
c:\windows\system32\o4Patch.exe
c:\windows\system32\oedlgb.dll
c:\windows\system32\oftqkpct.dll
c:\windows\system32\pcfsaceq.ini
c:\windows\system32\Process.exe
c:\windows\system32\pxfgen.dll
c:\windows\system32\qsyigwrc.dll
c:\windows\system32\rhfbyrok.ini
c:\windows\system32\rixhoueg.dll
c:\windows\system32\rmuwylxl.dll
c:\windows\system32\rwwuctds.dll
c:\windows\system32\SrchSTS.exe
c:\windows\system32\tkdmzg.dll
c:\windows\system32\tmp.reg
c:\windows\system32\VACFix.exe
c:\windows\system32\VCCLSID.exe
c:\windows\system32\wini104552502.exe
c:\windows\system32\wpv671228549770.cpx
c:\windows\system32\wpv911229907513.cpx
c:\windows\system32\WS2Fix.exe
c:\windows\system32\xhedsz.dll
c:\windows\system32\yayvUklJ.dll
c:\windows\system32\yayvWqoM.dll
c:\windows\system32\ygfjkmyh.dll
c:\windows\system32\ylqtbsun.ini
c:\windows\system32\ymoovdvd.ini
c:\windows\Tasks\rsdnrszb.job
c:\windows\wiaserviv.log
C:\xcrashdump.dat

----- BITS: Possible infected sites -----

hxxp://childhe.com
Infected copy of c:\windows\system32\winlogon.exe was found and disinfected
Restored copy from - c:\windows\ServicePackFiles\i386\winlogon.exe


.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Legacy_NTLOGIN32
-------\Service_ntlogin32


((((((((((((((((((((((((( Files Created from 2008-12-09 to 2009-01-09 )))))))))))))))))))))))))))))))
.

2009-02-09 13:18 . 2009-02-09 13:18 <DIR> d-------- c:\program files\Sun
2009-01-03 21:16 . 2009-01-03 21:17 <DIR> d-------- c:\program files\Webtools
2009-01-03 21:07 . 2009-01-03 21:08 47,593 --a------ c:\windows\SYSTEM32\flokawkumnjn.exe
2008-12-23 12:16 . 2008-12-23 12:15 410,984 --a------ c:\windows\SYSTEM32\deploytk.dll
2008-12-23 12:16 . 2008-12-23 12:15 73,728 --a------ c:\windows\SYSTEM32\javacpl.cpl
2008-12-10 13:33 . 2008-12-28 12:59 <DIR> d-------- c:\windows\LMI9B.tmp

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-02-09 21:35 --------- d-----w c:\documents and settings\Joseph M Gopez Sr\Application Data\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
2009-02-09 21:32 --------- d-----w c:\program files\Common Files\Adobe AIR
2009-02-09 21:29 --------- d-----w c:\program files\Common Files\Adobe
2009-01-09 07:55 --------- d-----w c:\program files\Network World iDemand
2009-01-09 07:55 --------- d-----w c:\documents and settings\Joseph M Gopez Sr\Application Data\Network World iDemand
2009-01-06 23:39 --------- d-----w c:\program files\Google
2008-12-23 20:15 --------- d-----w c:\program files\Java
2008-12-06 20:37 --------- d-----w c:\documents and settings\All Users\Application Data\vatknwli
2008-12-06 20:27 638 ----a-w c:\documents and settings\Joseph M Gopez Sr\xrt_log.dat
2008-11-26 08:56 --------- d-----w c:\program files\Enigma Software Group
2008-11-26 08:56 --------- d-----w c:\documents and settings\All Users\Application Data\Viewpoint
2008-11-23 22:42 27,136 ----a-w c:\documents and settings\Joseph M Gopez Sr\xrt_temp1.exe
2008-02-22 18:57 35,568 -c--a-w c:\documents and settings\Joseph M Gopez Sr\Application Data\GDIPFONTCACHEV1.DAT
2004-08-24 00:54 45,056 ----a-w c:\program files\Pivot Calculator1.1c.exe
.

------- Sigcheck -------

2002-08-29 03:00 200192 fe84e045a09a4abc4deef7270448b64e c:\windows\$NtServicePackUninstall$\termsrv.dll
2004-08-04 00:56 295424 b60c877d16d9c880b952fda04adf16e6 c:\windows\ServicePackFiles\i386\termsrv.dll
2008-10-09 23:25 295424 40ffc19a8d4875e9e19cecdc76ef9201 c:\windows\SYSTEM32\termsrv.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Network World iDemand"="c:\program files\Network World iDemand\Network World iDemand.exe" [2007-08-11 1537344]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2008-07-07 2156368]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2005-10-19 155648]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2005-10-19 126976]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2003-11-04 151597]
"DwlClient"="c:\program files\Common Files\Dell\EUSW\Support.exe" [2003-10-07 294912]
"ANIWZCSService"="c:\program files\Alpha Networks\ANIWZCS Service\WZCSLDR.exe" [2003-08-21 32768]
"IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2004-08-03 208952]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-08-11 7630848]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2006-08-11 86016]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2005-05-11 49152]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672]
"PCMService"="c:\program files\Dell\Media Experience\PCMService.exe" [2003-08-26 204800]
"D-Link Air Utility"="c:\program files\D-Link\Air Utility\AirCFG.exe" [2003-11-04 2502656]
"Adobe Photo Downloader"="c:\program files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe" [2005-06-06 57344]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2008-12-23 136600]
"nwiz"="nwiz.exe" [2006-08-11 c:\windows\SYSTEM32\nwiz.exe]

c:\documents and settings\Joseph M Gopez Sr\Start Menu\Programs\Startup\
PowerReg Scheduler.exe [2005-03-18 233472]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2003-11-04 24576]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
"setinfo"= {618685D1-4E5A-F8ED-18F2-01B95CF4F502} - c:\program files\guhaqdc\setinfo.dll [2008-10-09 94208]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.divxa32"= DivXa32.acm

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Authentication Packages REG_MULTI_SZ msv1_0 c:\windows\system32\yayvUklJ

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YPager.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"18635:TCP"= 18635:TCP:BitComet 18635 TCP
"6891:UDP"= 6891:UDP:BitComet 6891 UDP

R3 PRISM;D-Link Air Wireless Prism3 Adapter Driver;c:\windows\SYSTEM32\DRIVERS\PRISMNDS.sys [2005-10-29 652288]
S3 NETR33X;D-Link Air Wireless Adapter(RTL) NT Driver;c:\windows\SYSTEM32\DRIVERS\NETR33X.sys [2003-11-11 183680]
.
- - - - ORPHANS REMOVED - - - -

BHO-{3B0CD1C6-9CDE-41A2-8644-5C3AEFA9DBDC} - (no file)
BHO-{628B117B-0106-4443-B6C3-94311ED1117B} - (no file)
BHO-{6CC1435E-7FF8-4CF6-A35F-509A81EDB529} - c:\windows\system32\yayvUklJ.dll
BHO-{88EC2661-35AB-4E94-AC07-74686E9CE0A5} - (no file)
BHO-{A80D91C6-806A-4005-A153-BE9C9E599F9B} - (no file)
BHO-{BF950D8D-8A2A-491F-8CE6-E94E5DA9607F} - (no file)
BHO-{D6C414C3-C3CF-4512-B1DD-3EB2ECBB5DEC} - (no file)
HKCU-Run-ForbesInvesting - c:\program files\ForbesInvesting\ForbesInvestingAlerts.exe
HKCU-Run-ApiAdm - c:\windows\system32\oxexkziz.exe
HKCU-Run-updateMgr - c:\program files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe
HKCU-Run-Skype - c:\program files\Skype\Phone\Skype.exe
HKCU-Run-GetModule31 - c:\program files\GetModule\GetModule31.exe
HKCU-Run-swg - c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
HKLM-Run-NT Logging Service - syslog32.exe
HKLM-RunServices-Audoi Device Loader - smssv.exe
HKLM-RunServices-Microsoft System Checkup - libsysmgr.exe
Notify-__c00CE5A0 - c:\windows\system32\__c00CE5A0.dat
Notify-awtsPHxx - awtsPHxx.dll


.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com
mStart Page = hxxp://www.google.com
IE: &Yahoo! Search - file:///c:\program files\Yahoo!\Common/ycsrch.htm
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000
IE: Yahoo! &Dictionary - file:///c:\program files\Yahoo!\Common/ycdict.htm
IE: Yahoo! &Maps - file:///c:\program files\Yahoo!\Common/ycmap.htm
IE: Yahoo! &SMS - file:///c:\program files\Yahoo!\Common/ycsms.htm
Trusted Zone: vandemo.rjobrien.com
Trusted Zone: vanweb.rjobrien.com

O16 -: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
c:\windows\Downloaded Program Files\Microsoft XML Parser for Java.osd

O16 -: {BF116476-3238-4EDA-A2D7-6D6814EF0DEC} - hxxp://scpwbe.ops.placeware.com/etc/place/RCC-BETA/pws-pw-03/5.1.0.121/lib/quicksilver.cab
c:\windows\Downloaded Program Files\Quicksilver.inf
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-01-08 23:55:21
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
DwlClient = c:\program files\Common Files\Dell\EUSW\Support.exe?l?e?s?\?D?e?l?l?\?E?U?S?W?\?S?u?p?p?o?r?t?.?e?x?e???x???x???????????????????x???H???????x???x???????????x???????????x???x??????????????????????????????????????????w????????????j??w????x???x??????????????
NT Logging Service = syslog32.exe?
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices
Microsoft System Checkup = libsysmgr.exe?

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(664)
c:\windows\system32\midimap.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Java\jre6\bin\jqs.exe
c:\windows\SYSTEM32\nvsvc32.exe
c:\windows\SYSTEM32\wdfmgr.exe
c:\windows\SYSTEM32\rundll32.exe
c:\program files\Dell\Support\Alert\bin\NotifyAlert.exe
c:\windows\SYSTEM32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2009-01-09 0:00:00 - machine was rebooted [Joseph M Gopez Sr]
ComboFix-quarantined-files.txt 2009-01-09 07:59:18

Pre-Run: 27,651,829,760 bytes free
Post-Run: 28,127,412,224 bytes free

246

Now here is a new Hijack This log:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:05:11 AM, on 1/9/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0011)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Common Files\Dell\EUSW\Support.exe
C:\Program Files\Alpha Networks\ANIWZCS Service\WZCSLDR.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Dell\Media Experience\PCMService.exe
C:\Program Files\D-Link\Air Utility\AirCFG.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Network World iDemand\Network World iDemand.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Dell\Support\Alert\bin\NotifyAlert.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Documents and Settings\Joseph M Gopez Sr\Desktop\HiJackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn2\yt.dll
O3 - Toolbar: (no name) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - (no file)
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [DwlClient] C:\Program Files\Common Files\Dell\EUSW\Support.exe
O4 - HKLM\..\Run: [ANIWZCSService] C:\Program Files\Alpha Networks\ANIWZCS Service\WZCSLDR.exe
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
O4 - HKLM\..\Run: [D-Link Air Utility] C:\Program Files\D-Link\Air Utility\AirCFG.exe
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKCU\..\Run: [Network World iDemand] "C:\Program Files\Network World iDemand\Network World iDemand.exe" -r
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - Startup: PowerReg Scheduler.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://download.divx.com/player/DivXBrowserPlugin.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061...all/xscan53.cab
O16 - DPF: {BF116476-3238-4EDA-A2D7-6D6814EF0DEC} (Quicksilver Class) - http://scpwbe.ops.placeware.com/etc/place/...quicksilver.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll (file missing)
O21 - SSODL: setinfo - {618685D1-4E5A-F8ED-18F2-01B95CF4F502} - C:\Program Files\guhaqdc\setinfo.dll
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe

--
End of file - 6561 bytes
Thank you very much for your help so far.

#6 fenzodahl512

fenzodahl512

  • Members
  • 6,738 posts
  • OFFLINE
  •  
  • Local time:06:41 AM

Posted 09 January 2009 - 10:20 AM

Please download the OTMoveIt3 by OldTimer
  • Save it to your Desktop.
  • Please double-click OTMoveIt3.exe to run it. (Vista users, please right click on OTMoveit3.exe and select "Run as an Administrator")
  • Let the Unregister Dll's and Ocx's remain ticked and Zip Files After Moves remain unticked..
  • Copy the codebox contents and paste it to the "Paste List of Files/Folders to Move" window (under the light Yellow bar)

    :processes
    explorer.exe
    
    :services
    
    :files
    c:\windows\SYSTEM32\flokawkumnjn.exe
    c:\documents and settings\Joseph M Gopez Sr\xrt_temp1.exe
    c:\documents and settings\Joseph M Gopez Sr\xrt_log.dat
    c:\documents and settings\All Users\Application Data\vatknwli
    c:\program files\guhaqdc
    c:\documents and settings\Joseph M Gopez Sr\Start Menu\Programs\Startup\PowerReg Scheduler.exe
    
    :reg
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
    "setinfo"=-
    
    :commands
    [purity]
    [emptytemp]
    [start explorer]
    [reboot]
  • Click the red Moveit! button.
  • A log of files and folders moved will be created in the c:\_OTMoveIt\MovedFiles folder in the form of Date and Time (mmddyyyy_hhmmss.log). Please open this log in Notepad and post its contents in your next reply.
  • Close OTMoveIt3
If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes.




Please run a free online scan with the ESET Online Scanner
Note: You will need to use Internet Explorer for this scan.
  • Tick the box next to YES, I accept the Terms of Use.
  • Click Start
  • When asked, allow the ActiveX control to install
  • Click Start
  • Make sure that the options Remove found threats and the option Scan unwanted applications is checked
  • Click Scan
    Wait for the scan to finish
  • Use Notepad to open the logfile located at C:\Program Files\EsetOnlineScanner\log.txt
  • Copy and paste that log as a reply to this topic



Run RSIT again.. Post these logs in your next reply..

1. OTMoveIT3
2. ESET
3. RSIT log.txt

Keep calm, make it simple, use your brain, don't freak out, and you'll be just fine..
Awesomeness: When I get sad, I stop being sad and be awesome instead.. True story - Barney Stinson
Posted Image Posted Image
Its gonna be legen.. wait for it.. dary! Cherish the pain, it means you're still alive


#7 megaxz8642

megaxz8642
  • Topic Starter

  • Members
  • 11 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:02:41 PM

Posted 13 January 2009 - 02:10 AM

Here is the OTMoveit log:
========== PROCESSES ==========
Process explorer.exe killed successfully.
========== SERVICES/DRIVERS ==========
========== FILES ==========
c:\windows\SYSTEM32\flokawkumnjn.exe moved successfully.
c:\documents and settings\Joseph M Gopez Sr\xrt_temp1.exe moved successfully.
c:\documents and settings\Joseph M Gopez Sr\xrt_log.dat moved successfully.
c:\documents and settings\All Users\Application Data\vatknwli moved successfully.
c:\program files\guhaqdc moved successfully.
c:\documents and settings\Joseph M Gopez Sr\Start Menu\Programs\Startup\PowerReg Scheduler.exe moved successfully.
========== REGISTRY ==========
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\\setinfo deleted successfully.
========== COMMANDS ==========
File delete failed. C:\DOCUME~1\JOSEPH~1\LOCALS~1\Temp\Perflib_Perfdata_1d8.dat scheduled to be deleted on reboot.
User's Temp folder emptied.
User's Temporary Internet Files folder emptied.
User's Internet Explorer cache folder emptied.
Local Service Temp folder emptied.
File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\INDEX.DAT scheduled to be deleted on reboot.
Local Service Temporary Internet Files folder emptied.
File delete failed. C:\WINDOWS\temp\Perflib_Perfdata_5d0.dat scheduled to be deleted on reboot.
Windows Temp folder emptied.
Java cache emptied.
Temp folders emptied.
Explorer started successfully

OTMoveIt3 by OldTimer - Version 1.0.8.0 log created on 01112009_004340

Files moved on Reboot...
File C:\DOCUME~1\JOSEPH~1\LOCALS~1\Temp\Perflib_Perfdata_1d8.dat not found!
File move failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\INDEX.DAT scheduled to be moved on reboot.
File C:\WINDOWS\temp\Perflib_Perfdata_5d0.dat not found!

Here is ESET:
# version=4
# OnlineScanner.ocx=1.0.0.56
# OnlineScannerDLLA.dll=1, 0, 0, 51
# OnlineScannerDLLW.dll=1, 0, 0, 51
# OnlineScannerUninstaller.exe=1, 0, 0, 49
# vers_standard_module=3760 (20090112)
# vers_arch_module=1.064 (20080214)
# vers_adv_heur_module=1.066 (20070917)
# EOSSerial=d5b83a9770444d41a20a447165314567
# end=finished
# remove_checked=true
# unwanted_checked=true
# utc_time=2009-01-13 06:13:34
# local_time=2009-01-12 10:13:34 (-0800, Pacific Standard Time)
# country="United States"
# osver=5.1.2600 NT Service Pack 2
# scanned=300857
# found=2
# scan_time=2720
C:\WINDOWS\SYSTEM32\DRIVERS\ETC\hosts.20081010-021557.backup Win32/Qhosts trojan (unable to clean - deleted) 00000000000000000000000000000000
C:\_OTMoveIt\MovedFiles\01112009_004340\program files\guhaqdc\setinfo.dll Win32/BHO.NHN trojan (unable to clean - deleted) 00000000000000000000000000000000

Here is RSIT:
Logfile of random's system information tool 1.05 (written by random/random)
Run by Joseph M Gopez Sr at 2009-01-12 23:08:27
Microsoft Windows XP Home Edition Service Pack 2
System drive C: has 26 GB (68%) free of 38 GB
Total RAM: 510 MB (25% free)

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:08:30 PM, on 1/12/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16762)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Common Files\Dell\EUSW\Support.exe
C:\Program Files\Alpha Networks\ANIWZCS Service\WZCSLDR.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Dell\Media Experience\PCMService.exe
C:\Program Files\D-Link\Air Utility\AirCFG.exe
C:\Program Files\Dell\Support\Alert\bin\NotifyAlert.exe
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Network World iDemand\Network World iDemand.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Documents and Settings\Joseph M Gopez Sr\Desktop\RSIT.exe
C:\Documents and Settings\Joseph M Gopez Sr\Desktop\Joseph M Gopez Sr.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn2\yt.dll
O3 - Toolbar: (no name) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - (no file)
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [DwlClient] C:\Program Files\Common Files\Dell\EUSW\Support.exe
O4 - HKLM\..\Run: [ANIWZCSService] C:\Program Files\Alpha Networks\ANIWZCS Service\WZCSLDR.exe
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
O4 - HKLM\..\Run: [D-Link Air Utility] C:\Program Files\D-Link\Air Utility\AirCFG.exe
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKCU\..\Run: [Network World iDemand] "C:\Program Files\Network World iDemand\Network World iDemand.exe" -r
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} (OnlineScanner Control) - http://www.eset.eu/OnlineScanner.cab
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://download.divx.com/player/DivXBrowserPlugin.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061...all/xscan53.cab
O16 - DPF: {BF116476-3238-4EDA-A2D7-6D6814EF0DEC} (Quicksilver Class) - http://scpwbe.ops.placeware.com/etc/place/...quicksilver.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll (file missing)
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe

--
End of file - 6585 bytes

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java™ Plug-In SSV Helper - C:\Program Files\Java\jre6\bin\ssv.dll [2008-12-23 320920]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java™ Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2008-12-23 34816]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{EF99BD32-C1FB-11D2-892F-0090271D4F88} - Yahoo! Toolbar - C:\Program Files\Yahoo!\Companion\Installs\cpn2\yt.dll [2005-11-21 399424]
{2318C2B1-4965-11d4-9B18-009027A5CD4F}

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"=C:\WINDOWS\system32\igfxtray.exe [2005-10-19 155648]
"HotKeysCmds"=C:\WINDOWS\system32\hkcmd.exe [2005-10-19 126976]
"TkBellExe"=C:\Program Files\Common Files\Real\Update_OB\realsched.exe [2003-11-04 151597]
"DwlClient"=C:\Program Files\Common Files\Dell\EUSW\Support.exe [2003-10-07 294912]
"ANIWZCSService"=C:\Program Files\Alpha Networks\ANIWZCS Service\WZCSLDR.exe [2003-08-21 32768]
"IMJPMIG8.1"=C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE [2004-08-03 208952]
"NvCplDaemon"=C:\WINDOWS\system32\NvCpl.dll [2006-08-11 7630848]
"nwiz"=nwiz.exe /install []
"NvMediaCenter"=C:\WINDOWS\system32\NvMcTray.dll [2006-08-11 86016]
"HP Software Update"=C:\Program Files\HP\HP Software Update\HPWuSchd2.exe [2005-05-11 49152]
"Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2008-06-12 34672]
"PCMService"=C:\Program Files\Dell\Media Experience\PCMService.exe [2003-08-26 204800]
"D-Link Air Utility"=C:\Program Files\D-Link\Air Utility\AirCFG.exe [2003-11-04 2502656]
"Adobe Photo Downloader"=C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe [2005-06-06 57344]
"SunJavaUpdateSched"=C:\Program Files\Java\jre6\bin\jusched.exe [2008-12-23 136600]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Network World iDemand"=C:\Program Files\Network World iDemand\Network World iDemand.exe [2007-08-11 1537344]
"ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe [2004-08-04 15360]
"SpybotSD TeaTimer"=C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe [2008-07-07 2156368]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup
Digital Line Detect.lnk - C:\Program Files\Digital Line Detect\DLG.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\WINDOWS\system32\igfxsrvc.dll [2005-10-19 348160]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa]
"authentication packages"=msv1_0
C:\WINDOWS\system32\yayvUklJ

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\UploadMgr]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=323
"NoDriveAutoRun"=67108863
"NoDrives"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveAutoRun"=
"NoDriveTypeAutoRun"=
"NoDrives"=

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\Yahoo!\Messenger\YPager.exe"="C:\Program Files\Yahoo!\Messenger\YPager.exe:*:Enabled:Yahoo! Messenger"
"C:\Program Files\Yahoo!\Messenger\YServer.exe"="C:\Program Files\Yahoo!\Messenger\YServer.exe:*:Enabled:Yahoo! FT Server"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"

======List of files/folders created in the last 3 months======

2009-02-09 13:35:34 ----D---- C:\Documents and Settings\Joseph M Gopez Sr\Application Data\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
2009-02-09 13:32:18 ----D---- C:\Program Files\Common Files\Adobe AIR
2009-02-09 13:18:45 ----D---- C:\Program Files\Sun
2009-01-12 23:08:27 ----D---- C:\rsit
2009-01-12 21:26:08 ----D---- C:\WINDOWS\LastGood
2009-01-11 00:53:15 ----D---- C:\Program Files\EsetOnlineScanner
2009-01-11 00:45:12 ----SHD---- C:\RECYCLER
2009-01-11 00:43:40 ----D---- C:\_OTMoveIt
2009-01-09 00:29:12 ----HDC---- C:\WINDOWS\$NtUninstallKB951376-v2$
2009-01-09 00:28:57 ----HDC---- C:\WINDOWS\$NtUninstallKB952954$
2009-01-09 00:28:39 ----HDC---- C:\WINDOWS\$NtUninstallKB946648$
2009-01-09 00:28:27 ----HDC---- C:\WINDOWS\$NtUninstallKB956803$
2009-01-09 00:28:14 ----HDC---- C:\WINDOWS\$NtUninstallKB952069_WM9$
2009-01-09 00:28:03 ----HDC---- C:\WINDOWS\$NtUninstallKB923723$
2009-01-09 00:27:35 ----HDC---- C:\WINDOWS\$NtUninstallKB955839$
2009-01-09 00:27:23 ----HDC---- C:\WINDOWS\$NtUninstallKB956391$
2009-01-09 00:27:09 ----HDC---- C:\WINDOWS\$NtUninstallKB957095$
2009-01-09 00:25:16 ----HDC---- C:\WINDOWS\$NtUninstallKB950974$
2009-01-09 00:24:59 ----HDC---- C:\WINDOWS\$NtUninstallKB951698$
2009-01-09 00:24:40 ----HDC---- C:\WINDOWS\$NtUninstallKB954211$
2009-01-09 00:23:46 ----HDC---- C:\WINDOWS\$NtUninstallKB956841$
2009-01-09 00:20:00 ----HDC---- C:\WINDOWS\$NtUninstallKB941569$
2009-01-09 00:18:24 ----HDC---- C:\WINDOWS\$NtUninstallKB953155$
2009-01-09 00:18:10 ----HDC---- C:\WINDOWS\$NtUninstallKB950762$
2009-01-09 00:17:57 ----HDC---- C:\WINDOWS\$NtUninstallKB957097$
2009-01-09 00:17:43 ----HDC---- C:\WINDOWS\$NtUninstallKB952287$
2009-01-09 00:17:29 ----HDC---- C:\WINDOWS\$NtUninstallKB951066$
2009-01-09 00:17:16 ----D---- C:\WINDOWS\ie7updates
2009-01-09 00:17:02 ----HDC---- C:\WINDOWS\$NtUninstallKB938464$
2009-01-09 00:16:47 ----HDC---- C:\WINDOWS\$NtUninstallKB954600$
2009-01-09 00:16:33 ----HDC---- C:\WINDOWS\$NtUninstallKB958644$
2009-01-09 00:16:15 ----HDC---- C:\WINDOWS\$NtUninstallKB955069$
2009-01-09 00:16:02 ----HDC---- C:\WINDOWS\$NtUninstallKB956802$
2009-01-09 00:14:52 ----D---- C:\Program Files\MSXML 4.0
2009-01-09 00:14:11 ----HDC---- C:\WINDOWS\$NtUninstallKB936782_WMP10$
2009-01-09 00:11:37 ----D---- C:\WINDOWS\system32\CatRoot_bak
2009-01-09 00:01:19 ----A---- C:\WINDOWS\system32\wucltui.dll.mui
2009-01-09 00:01:19 ----A---- C:\WINDOWS\system32\wuaueng.dll.mui
2009-01-09 00:01:18 ----A---- C:\WINDOWS\system32\wuapi.dll.mui
2009-01-09 00:00:02 ----A---- C:\ComboFix.txt
2009-01-08 23:38:41 ----A---- C:\WINDOWS\NIRCMD.exe
2009-01-07 14:15:09 ----A---- C:\CF-RC COMBO FIX 1st round.txt
2009-01-07 14:13:37 ----A---- C:\Boot.bak
2009-01-07 14:13:27 ----RASHD---- C:\cmdcons
2009-01-07 14:01:30 ----A---- C:\WINDOWS\zip.exe
2009-01-07 14:01:30 ----A---- C:\WINDOWS\VFIND.exe
2009-01-07 14:01:30 ----A---- C:\WINDOWS\SWXCACLS.exe
2009-01-07 14:01:30 ----A---- C:\WINDOWS\SWSC.exe
2009-01-07 14:01:30 ----A---- C:\WINDOWS\SWREG.exe
2009-01-07 14:01:30 ----A---- C:\WINDOWS\sed.exe
2009-01-07 14:01:30 ----A---- C:\WINDOWS\grep.exe
2009-01-07 14:01:30 ----A---- C:\WINDOWS\fdsv.exe
2009-01-07 14:01:15 ----D---- C:\WINDOWS\ERDNT
2009-01-07 14:01:15 ----D---- C:\Qoobox
2009-01-03 21:16:59 ----D---- C:\Program Files\Webtools
2008-12-23 12:16:27 ----A---- C:\WINDOWS\system32\javaws.exe
2008-12-23 12:16:27 ----A---- C:\WINDOWS\system32\javaw.exe
2008-12-23 12:16:27 ----A---- C:\WINDOWS\system32\java.exe
2008-12-23 12:16:27 ----A---- C:\WINDOWS\system32\deploytk.dll
2008-12-10 13:33:06 ----D---- C:\WINDOWS\LMI9B.tmp
2008-12-06 12:09:42 ----A---- C:\WINDOWS\system32\ef85e09b-.txt
2008-12-02 08:41:42 ----A---- C:\WINDOWS\system32\nst13.dll
2008-10-22 01:47:07 ----N---- C:\WINDOWS\system32\tzchange.exe

======List of files/folders modified in the last 3 months======

2009-02-09 13:36:03 ----D---- C:\Documents and Settings\All Users\Application Data\Adobe
2009-02-09 13:35:32 ----D---- C:\Documents and Settings\Joseph M Gopez Sr\Application Data\Adobe
2009-02-09 13:32:37 ----D---- C:\Program Files\Adobe
2009-02-09 13:29:26 ----D---- C:\Program Files\Common Files\Adobe
2009-01-12 21:27:45 ----SD---- C:\WINDOWS\Downloaded Program Files
2009-01-12 21:27:45 ----D---- C:\WINDOWS\Temp
2009-01-12 21:27:45 ----D---- C:\WINDOWS\SYSTEM32
2009-01-12 21:26:08 ----D---- C:\WINDOWS
2009-01-12 21:25:24 ----D---- C:\WINDOWS\system32\CatRoot2
2009-01-12 21:23:39 ----A---- C:\WINDOWS\WIN.INI
2009-01-12 21:21:04 ----D---- C:\Program Files\Network World iDemand
2009-01-12 21:21:04 ----D---- C:\Documents and Settings\Joseph M Gopez Sr\Application Data\Network World iDemand
2009-01-12 21:20:47 ----A---- C:\WINDOWS\ModemLog_Conexant D850 56K V.9x DFVc Modem.txt
2009-01-11 02:15:10 ----A---- C:\WINDOWS\SchedLgU.Txt
2009-01-11 02:13:51 ----D---- C:\WINDOWS\system32\CatRoot
2009-01-11 02:13:47 ----HD---- C:\WINDOWS\INF
2009-01-11 00:53:15 ----AD---- C:\Program Files
2009-01-11 00:34:03 ----D---- C:\WINDOWS\Prefetch
2009-01-11 00:32:48 ----RSHDC---- C:\WINDOWS\system32\DLLCACHE
2009-01-11 00:31:40 ----HD---- C:\Config.Msi
2009-01-09 00:29:16 ----D---- C:\WINDOWS\system32\DRIVERS
2009-01-09 00:29:11 ----HD---- C:\WINDOWS\$hf_mig$
2009-01-09 00:29:07 ----A---- C:\WINDOWS\imsins.BAK
2009-01-09 00:28:43 ----D---- C:\Program Files\Messenger
2009-01-09 00:26:43 ----D---- C:\WINDOWS\system32\en-US
2009-01-09 00:26:42 ----D---- C:\Program Files\Internet Explorer
2009-01-09 00:22:24 ----SHD---- C:\WINDOWS\Installer
2009-01-09 00:17:04 ----D---- C:\WINDOWS\WinSxS
2009-01-09 00:01:33 ----D---- C:\WINDOWS\SoftwareDistribution
2009-01-09 00:01:33 ----D---- C:\WINDOWS\Help
2009-01-08 23:55:25 ----A---- C:\WINDOWS\system.ini
2009-01-08 23:53:04 ----D---- C:\WINDOWS\system32\CONFIG
2009-01-08 23:46:27 ----D---- C:\WINDOWS\AppPatch
2009-01-08 23:46:27 ----D---- C:\Program Files\Common Files
2009-01-08 23:45:21 ----SD---- C:\WINDOWS\Tasks
2009-01-07 14:13:37 ----RASH---- C:\boot.ini
2009-01-06 15:39:23 ----D---- C:\Program Files\Google
2009-01-03 21:22:13 ----D---- C:\Documents and Settings\All Users\Application Data\Google
2008-12-23 12:15:43 ----D---- C:\Program Files\Java
2008-12-12 22:40:02 ----A---- C:\WINDOWS\system32\mshtml.dll
2008-12-10 14:30:17 ----RSD---- C:\WINDOWS\assembly
2008-12-10 14:30:17 ----D---- C:\WINDOWS\Microsoft.NET
2008-12-10 13:46:05 ----D---- C:\WINDOWS\PCHealth
2008-12-09 15:24:38 ----A---- C:\WINDOWS\system32\MRT.exe
2008-11-26 00:56:22 ----D---- C:\Program Files\Enigma Software Group
2008-11-26 00:56:05 ----D---- C:\Documents and Settings\All Users\Application Data\Viewpoint
2008-11-09 12:43:59 ----D---- C:\WINDOWS\network diagnostic
2008-11-09 12:34:15 ----D---- C:\WINDOWS\pss
2008-11-02 13:55:09 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2008-10-23 05:01:36 ----A---- C:\WINDOWS\system32\gdi32.dll
2008-10-16 22:38:34 ----A---- C:\rapport.txt
2008-10-16 22:37:17 ----A---- C:\WINDOWS\system32\tmp.txt
2008-10-16 14:13:40 ----A---- C:\WINDOWS\system32\wuweb.dll
2008-10-16 14:13:40 ----A---- C:\WINDOWS\system32\wuaueng.dll
2008-10-16 14:12:22 ----A---- C:\WINDOWS\system32\wucltui.dll
2008-10-16 14:12:20 ----A---- C:\WINDOWS\system32\wuapi.dll
2008-10-16 14:09:44 ----A---- C:\WINDOWS\system32\wups2.dll
2008-10-16 14:09:44 ----A---- C:\WINDOWS\system32\wuauclt.exe
2008-10-16 14:09:44 ----A---- C:\WINDOWS\system32\cdm.dll
2008-10-16 14:08:58 ----A---- C:\WINDOWS\system32\wups.dll
2008-10-16 12:38:40 ----A---- C:\WINDOWS\system32\wininet.dll
2008-10-16 12:38:39 ----A---- C:\WINDOWS\system32\webcheck.dll
2008-10-16 12:38:39 ----A---- C:\WINDOWS\system32\urlmon.dll
2008-10-16 12:38:39 ----A---- C:\WINDOWS\system32\url.dll
2008-10-16 12:38:39 ----A---- C:\WINDOWS\system32\pngfilt.dll
2008-10-16 12:38:39 ----A---- C:\WINDOWS\system32\occache.dll
2008-10-16 12:38:39 ----A---- C:\WINDOWS\system32\mstime.dll
2008-10-16 12:38:38 ----A---- C:\WINDOWS\system32\msrating.dll
2008-10-16 12:38:38 ----A---- C:\WINDOWS\system32\mshtmled.dll
2008-10-16 12:38:37 ----A---- C:\WINDOWS\system32\msfeedsbs.dll
2008-10-16 12:38:37 ----A---- C:\WINDOWS\system32\msfeeds.dll
2008-10-16 12:38:37 ----A---- C:\WINDOWS\system32\jsproxy.dll
2008-10-16 12:38:37 ----A---- C:\WINDOWS\system32\iertutil.dll
2008-10-16 12:38:37 ----A---- C:\WINDOWS\system32\iernonce.dll
2008-10-16 12:38:37 ----A---- C:\WINDOWS\system32\ieframe.dll
2008-10-16 12:38:35 ----A---- C:\WINDOWS\system32\iedkcs32.dll
2008-10-16 12:38:35 ----A---- C:\WINDOWS\system32\ieapfltr.dll
2008-10-16 12:38:35 ----A---- C:\WINDOWS\system32\ieaksie.dll
2008-10-16 12:38:35 ----A---- C:\WINDOWS\system32\ieakeng.dll
2008-10-16 12:38:35 ----A---- C:\WINDOWS\system32\icardie.dll
2008-10-16 12:38:35 ----A---- C:\WINDOWS\system32\extmgr.dll
2008-10-16 12:38:34 ----A---- C:\WINDOWS\system32\dxtrans.dll
2008-10-16 12:38:34 ----A---- C:\WINDOWS\system32\dxtmsft.dll
2008-10-16 12:38:34 ----A---- C:\WINDOWS\system32\advpack.dll
2008-10-16 05:11:09 ----A---- C:\WINDOWS\system32\ieudinit.exe
2008-10-16 05:11:09 ----A---- C:\WINDOWS\system32\ie4uinit.exe
2008-10-15 08:57:55 ----A---- C:\WINDOWS\system32\netapi32.dll
2008-10-14 23:04:53 ----A---- C:\WINDOWS\system32\ieakui.dll

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R1 intelppm;Intel Processor Driver; C:\WINDOWS\System32\DRIVERS\intelppm.sys [2004-08-03 36096]
R1 omci;OMCI WDM Device Driver; C:\WINDOWS\System32\DRIVERS\omci.sys [2002-11-08 17217]
R2 mdmxsdk;mdmxsdk; C:\WINDOWS\System32\DRIVERS\mdmxsdk.sys [2003-04-09 11043]
R3 aeaudio;aeaudio; C:\WINDOWS\system32\drivers\aeaudio.sys [2002-04-01 4816]
R3 bcm4sbxp;Broadcom 440x 10/100 Integrated Controller XP Driver; C:\WINDOWS\System32\DRIVERS\bcm4sbxp.sys [2003-05-23 43136]
R3 HSF_DP;HSF_DP; C:\WINDOWS\System32\DRIVERS\HSF_DP.sys [2003-11-17 1042432]
R3 HSFHWBS2;HSFHWBS2; C:\WINDOWS\System32\DRIVERS\HSFHWBS2.sys [2003-11-17 212224]
R3 ialm;ialm; C:\WINDOWS\System32\DRIVERS\ialmnt5.sys [2005-10-19 807998]
R3 MODEMCSA;Unimodem Streaming Filter Device; C:\WINDOWS\system32\drivers\MODEMCSA.sys [2001-08-17 16128]
R3 nv;nv; C:\WINDOWS\System32\DRIVERS\nv4_mini.sys [2006-08-11 3958496]
R3 PRISM;D-Link Air Wireless Prism3 Adapter Driver; C:\WINDOWS\System32\DRIVERS\PRISMNDS.sys [2003-09-18 652288]
R3 smwdm;smwdm; C:\WINDOWS\system32\drivers\smwdm.sys [2003-02-28 545024]
R3 usbehci;Microsoft USB 2.0 Enhanced Host Controller Miniport Driver; C:\WINDOWS\System32\DRIVERS\usbehci.sys [2004-08-03 26624]
R3 usbhub;USB2 Enabled Hub; C:\WINDOWS\System32\DRIVERS\usbhub.sys [2004-08-03 57600]
R3 usbuhci;Microsoft USB Universal Host Controller Miniport Driver; C:\WINDOWS\System32\DRIVERS\usbuhci.sys [2004-08-03 20480]
R3 winachsf;winachsf; C:\WINDOWS\System32\DRIVERS\HSF_CNXT.sys [2003-11-17 680704]
S1 P3;Intel PentiumIII Processor Driver; C:\WINDOWS\System32\DRIVERS\p3.sys [2004-08-03 42496]
S3 {6080A529-897E-4629-A488-ABA0C29B635E};Intel® Graphics Platform (SoftBIOS) Driver; C:\WINDOWS\system32\drivers\ialmsbw.sys [2003-04-15 113504]
S3 {D31A0762-0CEB-444e-ACFF-B049A1F6FE91};Intel® Graphics Chipset (KCH) Driver; C:\WINDOWS\system32\drivers\ialmkchw.sys [2003-04-15 78752]
S3 bvrp_pci;bvrp_pci; C:\WINDOWS\system32\drivers\bvrp_pci.sys []
S3 EL90XBC;3Com EtherLink XL 90XB/C Adapter Driver; C:\WINDOWS\System32\DRIVERS\el90xbc5.sys []
S3 HidUsb;Microsoft HID Class Driver; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2001-08-17 9600]
S3 i81x;i81x; C:\WINDOWS\System32\DRIVERS\i81xnt5.sys [2004-08-03 161020]
S3 iAimFP0;iAimFP0; C:\WINDOWS\System32\DRIVERS\wADV01nt.sys [2004-08-03 12415]
S3 iAimFP1;iAimFP1; C:\WINDOWS\System32\DRIVERS\wADV02NT.sys [2004-08-03 12127]
S3 iAimFP2;iAimFP2; C:\WINDOWS\System32\DRIVERS\wADV05NT.sys [2004-08-03 11775]
S3 iAimFP3;iAimFP3; C:\WINDOWS\System32\DRIVERS\wSiINTxx.sys [2004-08-03 12063]
S3 iAimFP4;iAimFP4; C:\WINDOWS\System32\DRIVERS\wVchNTxx.sys [2004-08-03 19455]
S3 iAimTV0;iAimTV0; C:\WINDOWS\System32\DRIVERS\wATV01nt.sys [2004-08-03 29311]
S3 iAimTV1;iAimTV1; C:\WINDOWS\System32\DRIVERS\wATV02NT.sys [2004-08-03 19551]
S3 iAimTV2;iAimTV2; C:\WINDOWS\System32\DRIVERS\wATV03nt.sys []
S3 iAimTV3;iAimTV3; C:\WINDOWS\System32\DRIVERS\wATV04nt.sys [2004-08-03 33599]
S3 iAimTV4;iAimTV4; C:\WINDOWS\System32\DRIVERS\wCh7xxNT.sys [2004-08-03 23615]
S3 mouhid;Mouse HID Driver; C:\WINDOWS\System32\DRIVERS\mouhid.sys [2001-08-17 12160]
S3 NETR33X;D-Link Air Wireless Adapter(RTL) NT Driver; C:\WINDOWS\System32\DRIVERS\NETR33X.SYS [2003-11-11 183680]
S3 PalmUSBD;PalmUSBD; C:\WINDOWS\system32\drivers\PalmUSBD.sys [2004-03-04 16509]
S3 RT2500;Linksys Wireless-G PCI Adapter Driver; C:\WINDOWS\system32\DRIVERS\RT2500.sys [2005-04-21 242176]
S3 usbprint;Microsoft USB PRINTER Class; C:\WINDOWS\System32\DRIVERS\usbprint.sys [2004-08-03 25856]
S3 usbscan;USB Scanner Driver; C:\WINDOWS\System32\DRIVERS\usbscan.sys [2004-08-03 15104]
S3 USBSTOR;USB Mass Storage Driver; C:\WINDOWS\System32\DRIVERS\USBSTOR.SYS [2004-08-03 26496]
S3 wanatw;WAN Miniport (ATW); C:\WINDOWS\System32\DRIVERS\wanatw4.sys []
S3 WpdUsb;WpdUsb; C:\WINDOWS\System32\Drivers\wpdusb.sys [2005-01-28 18944]
S4 agp440;Intel AGP Bus Filter; C:\WINDOWS\System32\DRIVERS\agp440.sys [2004-08-03 42368]
S4 agpCPQ;Compaq AGP Bus Filter; C:\WINDOWS\System32\DRIVERS\agpCPQ.sys [2004-08-03 44928]
S4 alim1541;ALI AGP Bus Filter; C:\WINDOWS\System32\DRIVERS\alim1541.sys [2004-08-03 42752]
S4 amdagp;AMD AGP Bus Filter Driver; C:\WINDOWS\System32\DRIVERS\amdagp.sys [2004-08-03 43008]
S4 cbidf;cbidf; C:\WINDOWS\System32\DRIVERS\cbidf2k.sys [2003-07-16 13952]
S4 IntelIde;IntelIde; C:\WINDOWS\System32\DRIVERS\intelide.sys [2004-08-03 5504]
S4 sisagp;SIS AGP Bus Filter; C:\WINDOWS\System32\DRIVERS\sisagp.sys [2004-08-03 41088]
S4 viaagp;VIA AGP Bus Filter; C:\WINDOWS\System32\DRIVERS\viaagp.sys [2004-08-03 42240]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2008-12-23 152984]
R2 NVSvc;NVIDIA Display Driver Service; C:\WINDOWS\system32\nvsvc32.exe [2006-08-11 155715]
R2 UMWdf;Windows User Mode Driver Framework; C:\WINDOWS\System32\wdfmgr.exe [2005-01-28 38912]
S2 Fax;Fax; C:\WINDOWS\system32\fxssvc.exe [2004-08-04 267776]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2005-09-23 29896]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2005-09-23 66240]
S3 usprserv;User Privilege Service; C:\WINDOWS\System32\svchost.exe [2004-08-04 14336]

-----------------EOF-----------------

#8 fenzodahl512

fenzodahl512

  • Members
  • 6,738 posts
  • OFFLINE
  •  
  • Local time:06:41 AM

Posted 13 January 2009 - 07:10 AM

Almost there.. Do OTMoveIt3 step again but this time with below script


:reg
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa]
"Authentication Packages"=hex(7):6d,73,76,31,5f,30,00,00
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}"=-



Run RSIT again.. Post me these logs in your next reply..

1. OTMoveIt3
2. RSIT log.txt
3. How's the computer now? :thumbsup:

Edited by fenzodahl512, 13 January 2009 - 07:11 AM.

Keep calm, make it simple, use your brain, don't freak out, and you'll be just fine..
Awesomeness: When I get sad, I stop being sad and be awesome instead.. True story - Barney Stinson
Posted Image Posted Image
Its gonna be legen.. wait for it.. dary! Cherish the pain, it means you're still alive


#9 megaxz8642

megaxz8642
  • Topic Starter

  • Members
  • 11 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:02:41 PM

Posted 13 January 2009 - 03:02 PM

Hi. My computer seems to be running just fine again. I am no longer redirected on websites, popups are gone, and the computer is no longer sluggish. Thank you so much for all your help.

Here is the moveit log:
========== REGISTRY ==========
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\"Authentication Packages"|hex(7):6d,73,76,31,5f,30,00,00 /E : value set successfully!
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar\\{2318C2B1-4965-11d4-9B18-009027A5CD4F} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2318C2B1-4965-11d4-9B18-009027A5CD4F}\ not found.

OTMoveIt3 by OldTimer - Version 1.0.8.0 log created on 01132009_115807

Here is the RSIT log:
Logfile of random's system information tool 1.05 (written by random/random)
Run by Joseph M Gopez Sr at 2009-01-13 12:00:03
Microsoft Windows XP Home Edition Service Pack 2
System drive C: has 26 GB (68%) free of 38 GB
Total RAM: 510 MB (43% free)

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:00:14 PM, on 1/13/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16762)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Common Files\Dell\EUSW\Support.exe
C:\Program Files\Alpha Networks\ANIWZCS Service\WZCSLDR.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Dell\Support\Alert\bin\NotifyAlert.exe
C:\Program Files\Dell\Media Experience\PCMService.exe
C:\Program Files\D-Link\Air Utility\AirCFG.exe
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Network World iDemand\Network World iDemand.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Documents and Settings\Joseph M Gopez Sr\Desktop\RSIT.exe
C:\Documents and Settings\Joseph M Gopez Sr\Desktop\Joseph M Gopez Sr.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn2\yt.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [DwlClient] C:\Program Files\Common Files\Dell\EUSW\Support.exe
O4 - HKLM\..\Run: [ANIWZCSService] C:\Program Files\Alpha Networks\ANIWZCS Service\WZCSLDR.exe
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
O4 - HKLM\..\Run: [D-Link Air Utility] C:\Program Files\D-Link\Air Utility\AirCFG.exe
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKCU\..\Run: [Network World iDemand] "C:\Program Files\Network World iDemand\Network World iDemand.exe" -r
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} (OnlineScanner Control) - http://www.eset.eu/OnlineScanner.cab
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://download.divx.com/player/DivXBrowserPlugin.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061...all/xscan53.cab
O16 - DPF: {BF116476-3238-4EDA-A2D7-6D6814EF0DEC} (Quicksilver Class) - http://scpwbe.ops.placeware.com/etc/place/...quicksilver.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll (file missing)
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe

--
End of file - 6540 bytes

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java™ Plug-In SSV Helper - C:\Program Files\Java\jre6\bin\ssv.dll [2008-12-23 320920]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java™ Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2008-12-23 34816]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{EF99BD32-C1FB-11D2-892F-0090271D4F88} - Yahoo! Toolbar - C:\Program Files\Yahoo!\Companion\Installs\cpn2\yt.dll [2005-11-21 399424]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"=C:\WINDOWS\system32\igfxtray.exe [2005-10-19 155648]
"HotKeysCmds"=C:\WINDOWS\system32\hkcmd.exe [2005-10-19 126976]
"TkBellExe"=C:\Program Files\Common Files\Real\Update_OB\realsched.exe [2003-11-04 151597]
"DwlClient"=C:\Program Files\Common Files\Dell\EUSW\Support.exe [2003-10-07 294912]
"ANIWZCSService"=C:\Program Files\Alpha Networks\ANIWZCS Service\WZCSLDR.exe [2003-08-21 32768]
"IMJPMIG8.1"=C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE [2004-08-03 208952]
"NvCplDaemon"=C:\WINDOWS\system32\NvCpl.dll [2006-08-11 7630848]
"nwiz"=nwiz.exe /install []
"NvMediaCenter"=C:\WINDOWS\system32\NvMcTray.dll [2006-08-11 86016]
"HP Software Update"=C:\Program Files\HP\HP Software Update\HPWuSchd2.exe [2005-05-11 49152]
"Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2008-06-12 34672]
"PCMService"=C:\Program Files\Dell\Media Experience\PCMService.exe [2003-08-26 204800]
"D-Link Air Utility"=C:\Program Files\D-Link\Air Utility\AirCFG.exe [2003-11-04 2502656]
"Adobe Photo Downloader"=C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe [2005-06-06 57344]
"SunJavaUpdateSched"=C:\Program Files\Java\jre6\bin\jusched.exe [2008-12-23 136600]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Network World iDemand"=C:\Program Files\Network World iDemand\Network World iDemand.exe [2007-08-11 1537344]
"ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe [2004-08-04 15360]
"SpybotSD TeaTimer"=C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe [2008-07-07 2156368]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup
Digital Line Detect.lnk - C:\Program Files\Digital Line Detect\DLG.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\WINDOWS\system32\igfxsrvc.dll [2005-10-19 348160]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\UploadMgr]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=323
"NoDriveAutoRun"=67108863
"NoDrives"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveAutoRun"=
"NoDriveTypeAutoRun"=
"NoDrives"=

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\Yahoo!\Messenger\YPager.exe"="C:\Program Files\Yahoo!\Messenger\YPager.exe:*:Enabled:Yahoo! Messenger"
"C:\Program Files\Yahoo!\Messenger\YServer.exe"="C:\Program Files\Yahoo!\Messenger\YServer.exe:*:Enabled:Yahoo! FT Server"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"

======List of files/folders created in the last 3 months======

2009-02-09 13:35:34 ----D---- C:\Documents and Settings\Joseph M Gopez Sr\Application Data\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
2009-02-09 13:32:18 ----D---- C:\Program Files\Common Files\Adobe AIR
2009-02-09 13:18:45 ----D---- C:\Program Files\Sun
2009-01-13 11:34:47 ----D---- C:\WINDOWS\LastGood
2009-01-12 23:08:27 ----D---- C:\rsit
2009-01-11 00:53:15 ----D---- C:\Program Files\EsetOnlineScanner
2009-01-11 00:45:12 ----SHD---- C:\RECYCLER
2009-01-11 00:43:40 ----D---- C:\_OTMoveIt
2009-01-09 00:29:12 ----HDC---- C:\WINDOWS\$NtUninstallKB951376-v2$
2009-01-09 00:28:57 ----HDC---- C:\WINDOWS\$NtUninstallKB952954$
2009-01-09 00:28:39 ----HDC---- C:\WINDOWS\$NtUninstallKB946648$
2009-01-09 00:28:27 ----HDC---- C:\WINDOWS\$NtUninstallKB956803$
2009-01-09 00:28:14 ----HDC---- C:\WINDOWS\$NtUninstallKB952069_WM9$
2009-01-09 00:28:03 ----HDC---- C:\WINDOWS\$NtUninstallKB923723$
2009-01-09 00:27:35 ----HDC---- C:\WINDOWS\$NtUninstallKB955839$
2009-01-09 00:27:23 ----HDC---- C:\WINDOWS\$NtUninstallKB956391$
2009-01-09 00:27:09 ----HDC---- C:\WINDOWS\$NtUninstallKB957095$
2009-01-09 00:25:16 ----HDC---- C:\WINDOWS\$NtUninstallKB950974$
2009-01-09 00:24:59 ----HDC---- C:\WINDOWS\$NtUninstallKB951698$
2009-01-09 00:24:40 ----HDC---- C:\WINDOWS\$NtUninstallKB954211$
2009-01-09 00:23:46 ----HDC---- C:\WINDOWS\$NtUninstallKB956841$
2009-01-09 00:20:00 ----HDC---- C:\WINDOWS\$NtUninstallKB941569$
2009-01-09 00:18:24 ----HDC---- C:\WINDOWS\$NtUninstallKB953155$
2009-01-09 00:18:10 ----HDC---- C:\WINDOWS\$NtUninstallKB950762$
2009-01-09 00:17:57 ----HDC---- C:\WINDOWS\$NtUninstallKB957097$
2009-01-09 00:17:43 ----HDC---- C:\WINDOWS\$NtUninstallKB952287$
2009-01-09 00:17:29 ----HDC---- C:\WINDOWS\$NtUninstallKB951066$
2009-01-09 00:17:16 ----D---- C:\WINDOWS\ie7updates
2009-01-09 00:17:02 ----HDC---- C:\WINDOWS\$NtUninstallKB938464$
2009-01-09 00:16:47 ----HDC---- C:\WINDOWS\$NtUninstallKB954600$
2009-01-09 00:16:33 ----HDC---- C:\WINDOWS\$NtUninstallKB958644$
2009-01-09 00:16:15 ----HDC---- C:\WINDOWS\$NtUninstallKB955069$
2009-01-09 00:16:02 ----HDC---- C:\WINDOWS\$NtUninstallKB956802$
2009-01-09 00:14:52 ----D---- C:\Program Files\MSXML 4.0
2009-01-09 00:14:11 ----HDC---- C:\WINDOWS\$NtUninstallKB936782_WMP10$
2009-01-09 00:11:37 ----D---- C:\WINDOWS\system32\CatRoot_bak
2009-01-09 00:01:19 ----A---- C:\WINDOWS\system32\wucltui.dll.mui
2009-01-09 00:01:19 ----A---- C:\WINDOWS\system32\wuaueng.dll.mui
2009-01-09 00:01:18 ----A---- C:\WINDOWS\system32\wuapi.dll.mui
2009-01-09 00:00:02 ----A---- C:\ComboFix.txt
2009-01-08 23:38:41 ----A---- C:\WINDOWS\NIRCMD.exe
2009-01-07 14:15:09 ----A---- C:\CF-RC COMBO FIX 1st round.txt
2009-01-07 14:13:37 ----A---- C:\Boot.bak
2009-01-07 14:13:27 ----RASHD---- C:\cmdcons
2009-01-07 14:01:30 ----A---- C:\WINDOWS\zip.exe
2009-01-07 14:01:30 ----A---- C:\WINDOWS\VFIND.exe
2009-01-07 14:01:30 ----A---- C:\WINDOWS\SWXCACLS.exe
2009-01-07 14:01:30 ----A---- C:\WINDOWS\SWSC.exe
2009-01-07 14:01:30 ----A---- C:\WINDOWS\SWREG.exe
2009-01-07 14:01:30 ----A---- C:\WINDOWS\sed.exe
2009-01-07 14:01:30 ----A---- C:\WINDOWS\grep.exe
2009-01-07 14:01:30 ----A---- C:\WINDOWS\fdsv.exe
2009-01-07 14:01:15 ----D---- C:\WINDOWS\ERDNT
2009-01-07 14:01:15 ----D---- C:\Qoobox
2009-01-03 21:16:59 ----D---- C:\Program Files\Webtools
2008-12-23 12:16:27 ----A---- C:\WINDOWS\system32\javaws.exe
2008-12-23 12:16:27 ----A---- C:\WINDOWS\system32\javaw.exe
2008-12-23 12:16:27 ----A---- C:\WINDOWS\system32\java.exe
2008-12-23 12:16:27 ----A---- C:\WINDOWS\system32\deploytk.dll
2008-12-10 13:33:06 ----D---- C:\WINDOWS\LMI9B.tmp
2008-12-06 12:09:42 ----A---- C:\WINDOWS\system32\ef85e09b-.txt
2008-12-02 08:41:42 ----A---- C:\WINDOWS\system32\nst13.dll
2008-10-22 01:47:07 ----N---- C:\WINDOWS\system32\tzchange.exe

======List of files/folders modified in the last 3 months======

2009-02-09 13:36:03 ----D---- C:\Documents and Settings\All Users\Application Data\Adobe
2009-02-09 13:35:32 ----D---- C:\Documents and Settings\Joseph M Gopez Sr\Application Data\Adobe
2009-02-09 13:32:37 ----D---- C:\Program Files\Adobe
2009-02-09 13:29:26 ----D---- C:\Program Files\Common Files\Adobe
2009-01-13 11:35:27 ----HD---- C:\WINDOWS\INF
2009-01-13 11:34:48 ----HD---- C:\WINDOWS\$hf_mig$
2009-01-13 11:34:47 ----D---- C:\WINDOWS
2009-01-13 11:34:46 ----D---- C:\WINDOWS\system32\CatRoot2
2009-01-13 11:31:20 ----D---- C:\WINDOWS\Temp
2009-01-13 11:31:16 ----A---- C:\WINDOWS\ModemLog_Conexant D850 56K V.9x DFVc Modem.txt
2009-01-13 11:31:13 ----D---- C:\Program Files\Network World iDemand
2009-01-13 11:31:13 ----D---- C:\Documents and Settings\Joseph M Gopez Sr\Application Data\Network World iDemand
2009-01-12 23:11:20 ----A---- C:\WINDOWS\SchedLgU.Txt
2009-01-12 21:27:45 ----SD---- C:\WINDOWS\Downloaded Program Files
2009-01-12 21:27:45 ----D---- C:\WINDOWS\SYSTEM32
2009-01-12 21:23:39 ----A---- C:\WINDOWS\WIN.INI
2009-01-11 02:13:51 ----D---- C:\WINDOWS\system32\CatRoot
2009-01-11 00:53:15 ----AD---- C:\Program Files
2009-01-11 00:34:03 ----D---- C:\WINDOWS\Prefetch
2009-01-11 00:32:48 ----RSHDC---- C:\WINDOWS\system32\DLLCACHE
2009-01-11 00:31:40 ----HD---- C:\Config.Msi
2009-01-09 00:29:16 ----D---- C:\WINDOWS\system32\DRIVERS
2009-01-09 00:29:07 ----A---- C:\WINDOWS\imsins.BAK
2009-01-09 00:28:43 ----D---- C:\Program Files\Messenger
2009-01-09 00:26:43 ----D---- C:\WINDOWS\system32\en-US
2009-01-09 00:26:42 ----D---- C:\Program Files\Internet Explorer
2009-01-09 00:22:24 ----SHD---- C:\WINDOWS\Installer
2009-01-09 00:17:04 ----D---- C:\WINDOWS\WinSxS
2009-01-09 00:01:33 ----D---- C:\WINDOWS\SoftwareDistribution
2009-01-09 00:01:33 ----D---- C:\WINDOWS\Help
2009-01-08 23:55:25 ----A---- C:\WINDOWS\system.ini
2009-01-08 23:53:04 ----D---- C:\WINDOWS\system32\CONFIG
2009-01-08 23:46:27 ----D---- C:\WINDOWS\AppPatch
2009-01-08 23:46:27 ----D---- C:\Program Files\Common Files
2009-01-08 23:45:21 ----SD---- C:\WINDOWS\Tasks
2009-01-07 14:13:37 ----RASH---- C:\boot.ini
2009-01-06 15:39:23 ----D---- C:\Program Files\Google
2009-01-03 21:22:13 ----D---- C:\Documents and Settings\All Users\Application Data\Google
2008-12-23 12:15:43 ----D---- C:\Program Files\Java
2008-12-12 22:40:02 ----A---- C:\WINDOWS\system32\mshtml.dll
2008-12-10 14:30:17 ----RSD---- C:\WINDOWS\assembly
2008-12-10 14:30:17 ----D---- C:\WINDOWS\Microsoft.NET
2008-12-10 13:46:05 ----D---- C:\WINDOWS\PCHealth
2008-12-09 15:24:38 ----A---- C:\WINDOWS\system32\MRT.exe
2008-11-26 00:56:22 ----D---- C:\Program Files\Enigma Software Group
2008-11-26 00:56:05 ----D---- C:\Documents and Settings\All Users\Application Data\Viewpoint
2008-11-09 12:43:59 ----D---- C:\WINDOWS\network diagnostic
2008-11-09 12:34:15 ----D---- C:\WINDOWS\pss
2008-11-02 13:55:09 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2008-10-23 05:01:36 ----A---- C:\WINDOWS\system32\gdi32.dll
2008-10-16 22:38:34 ----A---- C:\rapport.txt
2008-10-16 22:37:17 ----A---- C:\WINDOWS\system32\tmp.txt
2008-10-16 14:13:40 ----A---- C:\WINDOWS\system32\wuweb.dll
2008-10-16 14:13:40 ----A---- C:\WINDOWS\system32\wuaueng.dll
2008-10-16 14:12:22 ----A---- C:\WINDOWS\system32\wucltui.dll
2008-10-16 14:12:20 ----A---- C:\WINDOWS\system32\wuapi.dll
2008-10-16 14:09:44 ----A---- C:\WINDOWS\system32\wups2.dll
2008-10-16 14:09:44 ----A---- C:\WINDOWS\system32\wuauclt.exe
2008-10-16 14:09:44 ----A---- C:\WINDOWS\system32\cdm.dll
2008-10-16 14:08:58 ----A---- C:\WINDOWS\system32\wups.dll
2008-10-16 12:38:40 ----A---- C:\WINDOWS\system32\wininet.dll
2008-10-16 12:38:39 ----A---- C:\WINDOWS\system32\webcheck.dll
2008-10-16 12:38:39 ----A---- C:\WINDOWS\system32\urlmon.dll
2008-10-16 12:38:39 ----A---- C:\WINDOWS\system32\url.dll
2008-10-16 12:38:39 ----A---- C:\WINDOWS\system32\pngfilt.dll
2008-10-16 12:38:39 ----A---- C:\WINDOWS\system32\occache.dll
2008-10-16 12:38:39 ----A---- C:\WINDOWS\system32\mstime.dll
2008-10-16 12:38:38 ----A---- C:\WINDOWS\system32\msrating.dll
2008-10-16 12:38:38 ----A---- C:\WINDOWS\system32\mshtmled.dll
2008-10-16 12:38:37 ----A---- C:\WINDOWS\system32\msfeedsbs.dll
2008-10-16 12:38:37 ----A---- C:\WINDOWS\system32\msfeeds.dll
2008-10-16 12:38:37 ----A---- C:\WINDOWS\system32\jsproxy.dll
2008-10-16 12:38:37 ----A---- C:\WINDOWS\system32\iertutil.dll
2008-10-16 12:38:37 ----A---- C:\WINDOWS\system32\iernonce.dll
2008-10-16 12:38:37 ----A---- C:\WINDOWS\system32\ieframe.dll
2008-10-16 12:38:35 ----A---- C:\WINDOWS\system32\iedkcs32.dll
2008-10-16 12:38:35 ----A---- C:\WINDOWS\system32\ieapfltr.dll
2008-10-16 12:38:35 ----A---- C:\WINDOWS\system32\ieaksie.dll
2008-10-16 12:38:35 ----A---- C:\WINDOWS\system32\ieakeng.dll
2008-10-16 12:38:35 ----A---- C:\WINDOWS\system32\icardie.dll
2008-10-16 12:38:35 ----A---- C:\WINDOWS\system32\extmgr.dll
2008-10-16 12:38:34 ----A---- C:\WINDOWS\system32\dxtrans.dll
2008-10-16 12:38:34 ----A---- C:\WINDOWS\system32\dxtmsft.dll
2008-10-16 12:38:34 ----A---- C:\WINDOWS\system32\advpack.dll
2008-10-16 05:11:09 ----A---- C:\WINDOWS\system32\ieudinit.exe
2008-10-16 05:11:09 ----A---- C:\WINDOWS\system32\ie4uinit.exe
2008-10-15 08:57:55 ----A---- C:\WINDOWS\system32\netapi32.dll
2008-10-14 23:04:53 ----A---- C:\WINDOWS\system32\ieakui.dll

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R1 intelppm;Intel Processor Driver; C:\WINDOWS\System32\DRIVERS\intelppm.sys [2004-08-03 36096]
R1 omci;OMCI WDM Device Driver; C:\WINDOWS\System32\DRIVERS\omci.sys [2002-11-08 17217]
R2 mdmxsdk;mdmxsdk; C:\WINDOWS\System32\DRIVERS\mdmxsdk.sys [2003-04-09 11043]
R3 aeaudio;aeaudio; C:\WINDOWS\system32\drivers\aeaudio.sys [2002-04-01 4816]
R3 bcm4sbxp;Broadcom 440x 10/100 Integrated Controller XP Driver; C:\WINDOWS\System32\DRIVERS\bcm4sbxp.sys [2003-05-23 43136]
R3 HSF_DP;HSF_DP; C:\WINDOWS\System32\DRIVERS\HSF_DP.sys [2003-11-17 1042432]
R3 HSFHWBS2;HSFHWBS2; C:\WINDOWS\System32\DRIVERS\HSFHWBS2.sys [2003-11-17 212224]
R3 ialm;ialm; C:\WINDOWS\System32\DRIVERS\ialmnt5.sys [2005-10-19 807998]
R3 MODEMCSA;Unimodem Streaming Filter Device; C:\WINDOWS\system32\drivers\MODEMCSA.sys [2001-08-17 16128]
R3 nv;nv; C:\WINDOWS\System32\DRIVERS\nv4_mini.sys [2006-08-11 3958496]
R3 PRISM;D-Link Air Wireless Prism3 Adapter Driver; C:\WINDOWS\System32\DRIVERS\PRISMNDS.sys [2003-09-18 652288]
R3 smwdm;smwdm; C:\WINDOWS\system32\drivers\smwdm.sys [2003-02-28 545024]
R3 usbehci;Microsoft USB 2.0 Enhanced Host Controller Miniport Driver; C:\WINDOWS\System32\DRIVERS\usbehci.sys [2004-08-03 26624]
R3 usbhub;USB2 Enabled Hub; C:\WINDOWS\System32\DRIVERS\usbhub.sys [2004-08-03 57600]
R3 usbuhci;Microsoft USB Universal Host Controller Miniport Driver; C:\WINDOWS\System32\DRIVERS\usbuhci.sys [2004-08-03 20480]
R3 winachsf;winachsf; C:\WINDOWS\System32\DRIVERS\HSF_CNXT.sys [2003-11-17 680704]
S1 P3;Intel PentiumIII Processor Driver; C:\WINDOWS\System32\DRIVERS\p3.sys [2004-08-03 42496]
S3 {6080A529-897E-4629-A488-ABA0C29B635E};Intel® Graphics Platform (SoftBIOS) Driver; C:\WINDOWS\system32\drivers\ialmsbw.sys [2003-04-15 113504]
S3 {D31A0762-0CEB-444e-ACFF-B049A1F6FE91};Intel® Graphics Chipset (KCH) Driver; C:\WINDOWS\system32\drivers\ialmkchw.sys [2003-04-15 78752]
S3 bvrp_pci;bvrp_pci; C:\WINDOWS\system32\drivers\bvrp_pci.sys []
S3 EL90XBC;3Com EtherLink XL 90XB/C Adapter Driver; C:\WINDOWS\System32\DRIVERS\el90xbc5.sys []
S3 HidUsb;Microsoft HID Class Driver; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2001-08-17 9600]
S3 i81x;i81x; C:\WINDOWS\System32\DRIVERS\i81xnt5.sys [2004-08-03 161020]
S3 iAimFP0;iAimFP0; C:\WINDOWS\System32\DRIVERS\wADV01nt.sys [2004-08-03 12415]
S3 iAimFP1;iAimFP1; C:\WINDOWS\System32\DRIVERS\wADV02NT.sys [2004-08-03 12127]
S3 iAimFP2;iAimFP2; C:\WINDOWS\System32\DRIVERS\wADV05NT.sys [2004-08-03 11775]
S3 iAimFP3;iAimFP3; C:\WINDOWS\System32\DRIVERS\wSiINTxx.sys [2004-08-03 12063]
S3 iAimFP4;iAimFP4; C:\WINDOWS\System32\DRIVERS\wVchNTxx.sys [2004-08-03 19455]
S3 iAimTV0;iAimTV0; C:\WINDOWS\System32\DRIVERS\wATV01nt.sys [2004-08-03 29311]
S3 iAimTV1;iAimTV1; C:\WINDOWS\System32\DRIVERS\wATV02NT.sys [2004-08-03 19551]
S3 iAimTV2;iAimTV2; C:\WINDOWS\System32\DRIVERS\wATV03nt.sys []
S3 iAimTV3;iAimTV3; C:\WINDOWS\System32\DRIVERS\wATV04nt.sys [2004-08-03 33599]
S3 iAimTV4;iAimTV4; C:\WINDOWS\System32\DRIVERS\wCh7xxNT.sys [2004-08-03 23615]
S3 mouhid;Mouse HID Driver; C:\WINDOWS\System32\DRIVERS\mouhid.sys [2001-08-17 12160]
S3 NETR33X;D-Link Air Wireless Adapter(RTL) NT Driver; C:\WINDOWS\System32\DRIVERS\NETR33X.SYS [2003-11-11 183680]
S3 PalmUSBD;PalmUSBD; C:\WINDOWS\system32\drivers\PalmUSBD.sys [2004-03-04 16509]
S3 RT2500;Linksys Wireless-G PCI Adapter Driver; C:\WINDOWS\system32\DRIVERS\RT2500.sys [2005-04-21 242176]
S3 usbprint;Microsoft USB PRINTER Class; C:\WINDOWS\System32\DRIVERS\usbprint.sys [2004-08-03 25856]
S3 usbscan;USB Scanner Driver; C:\WINDOWS\System32\DRIVERS\usbscan.sys [2004-08-03 15104]
S3 USBSTOR;USB Mass Storage Driver; C:\WINDOWS\System32\DRIVERS\USBSTOR.SYS [2004-08-03 26496]
S3 wanatw;WAN Miniport (ATW); C:\WINDOWS\System32\DRIVERS\wanatw4.sys []
S3 WpdUsb;WpdUsb; C:\WINDOWS\System32\Drivers\wpdusb.sys [2005-01-28 18944]
S4 agp440;Intel AGP Bus Filter; C:\WINDOWS\System32\DRIVERS\agp440.sys [2004-08-03 42368]
S4 agpCPQ;Compaq AGP Bus Filter; C:\WINDOWS\System32\DRIVERS\agpCPQ.sys [2004-08-03 44928]
S4 alim1541;ALI AGP Bus Filter; C:\WINDOWS\System32\DRIVERS\alim1541.sys [2004-08-03 42752]
S4 amdagp;AMD AGP Bus Filter Driver; C:\WINDOWS\System32\DRIVERS\amdagp.sys [2004-08-03 43008]
S4 cbidf;cbidf; C:\WINDOWS\System32\DRIVERS\cbidf2k.sys [2003-07-16 13952]
S4 IntelIde;IntelIde; C:\WINDOWS\System32\DRIVERS\intelide.sys [2004-08-03 5504]
S4 sisagp;SIS AGP Bus Filter; C:\WINDOWS\System32\DRIVERS\sisagp.sys [2004-08-03 41088]
S4 viaagp;VIA AGP Bus Filter; C:\WINDOWS\System32\DRIVERS\viaagp.sys [2004-08-03 42240]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2008-12-23 152984]
R2 NVSvc;NVIDIA Display Driver Service; C:\WINDOWS\system32\nvsvc32.exe [2006-08-11 155715]
R2 UMWdf;Windows User Mode Driver Framework; C:\WINDOWS\System32\wdfmgr.exe [2005-01-28 38912]
S2 Fax;Fax; C:\WINDOWS\system32\fxssvc.exe [2004-08-04 267776]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2005-09-23 29896]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2005-09-23 66240]
S3 usprserv;User Privilege Service; C:\WINDOWS\System32\svchost.exe [2004-08-04 14336]

-----------------EOF-----------------

#10 fenzodahl512

fenzodahl512

  • Members
  • 6,738 posts
  • OFFLINE
  •  
  • Local time:06:41 AM

Posted 13 January 2009 - 09:35 PM

Looks good to me.. Lets do some cleanup...


Please download OTCleanIt and save it to Desktop.
  • Make sure you have internet connection..
  • Double-click OTCleanIt.exe
  • Click the CleanUp! button.
  • Select Yes when the "Begin cleanup Process?" prompt appears.
  • If you are prompted to Reboot during the cleanup, select Yes



Please read these excellent articles by miekiemoes :
Help! My computer is slow!
How to prevent Malware

Please reply to this thread once more and tell us about the computer behaviour before we can close this thread :thumbsup:



Have a safe and happy computing day!


Regards
fenzodahl512

Keep calm, make it simple, use your brain, don't freak out, and you'll be just fine..
Awesomeness: When I get sad, I stop being sad and be awesome instead.. True story - Barney Stinson
Posted Image Posted Image
Its gonna be legen.. wait for it.. dary! Cherish the pain, it means you're still alive


#11 megaxz8642

megaxz8642
  • Topic Starter

  • Members
  • 11 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:02:41 PM

Posted 19 January 2009 - 12:45 PM

Thank you very much for all your help! My computer appears to be in working order again. It is running just like it used to before infection. Thank you once again for all your help.




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users