Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

my antivirus "ESET NOD32" will close when i open it and all folders became application with a file size of 91.5


  • This topic is locked This topic is locked
3 replies to this topic

#1 josef_ralph

josef_ralph

  • Members
  • 1 posts
  • OFFLINE
  •  
  • Local time:03:19 PM

Posted 30 March 2009 - 08:52 PM

DDS (Ver_09-03-16.01) - NTFSx86
Run by Sirvertire at 9:33:04.84 on Tue 03/31/2009
Internet Explorer: 7.0.5730.11 BrowserJavaVersion: 1.6.0_11
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.479.43 [GMT 8:00]

AV: ESET NOD32 antivirus system 2.70 *On-access scanning enabled* (Updated)

============== Running Processes ===============

C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\Explorer.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe
C:\WINDOWS\system32\huelar.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.EXE
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\WINDOWS\winlogos.exe
C:\Documents and Settings\Sirvertire\Start Menu\Programs\Startup\mscvhost.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
D:\Microsoft Student with Encarta Premium 2007 DVD\EDICT.EXE
C:\Program Files\DAEMON Tools Lite\daemon.exe
C:\Program Files\DNA\btdna.exe
C:\PROGRA~1\COMMON~1\Nokia\MPAPI\MPAPI3s.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Common Files\PCSuite\Services\ServiceLayer.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Documents and Settings\Sirvertire\Desktop\dds.scr

============== Pseudo HJT Report ===============

uStart Page = hxxp://www.redtube.com/
uSearch Page = hxxp://www.google.com
uSearch Bar = hxxp://www.google.com/ie
uWindow Title = Huelar Browser
mDefault_Page_URL = hxxp://www.yahoo.com/
mDefault_Search_URL = hxxp://us.rd.yahoo.com/customize/ie/defaults/su/msgr8/*http://www.yahoo.com
mSearch Page = hxxp://us.rd.yahoo.com/customize/ie/defaults/sp/msgr8/*http://www.yahoo.com
mStart Page = hxxp://www.yahoo.com/
mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ie/defaults/su/msgr8/*http://www.yahoo.com
uURLSearchHooks: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\progra~1\yahoo!\companion\installs\cpn\yt.dll
mWinlogon: Shell=Explorer.exe huelar.exe
BHO: &Yahoo! Toolbar Helper: {02478d38-c3f9-4efb-9b51-7695eca05670} - c:\progra~1\yahoo!\companion\installs\cpn\yt.dll
BHO: AcroIEHlprObj Class: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 5.0\reader\activex\AcroIEHelper.ocx
BHO: D: {4457ff23-1ce5-30eb-9b43-3f7c39f8a521} - c:\windows\system32\xwr77204.dll
BHO: Yahoo! IE Services Button: {5bab4b5b-68bc-4b02-94d6-2fc0de4a7897} - c:\program files\yahoo!\common\yiesrvc.dll
BHO: Java™ Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre6\bin\ssv.dll
BHO: Encarta Web Companion Helper Object: {955be0b8-bc85-4caf-856e-8e0d8b610560} - c:\program files\common files\microsoft shared\encarta web companion\2007\ENCWCBAR.DLL
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\googletoolbar1.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: Encarta Web Companion: {147d6308-0614-4112-89b1-31402f9b82c4} - c:\program files\common files\microsoft shared\encarta web companion\2007\ENCWCBAR.DLL
TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\progra~1\yahoo!\companion\installs\cpn\yt.dll
TB: &Google: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\googletoolbar1.dll
TB: DAEMON Tools Toolbar: {32099aac-c132-4136-9e9a-4e364a424e17} - c:\program files\daemon tools toolbar\DTToolbar.dll
TB: {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - No File
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [PcSync] c:\program files\nokia\nokia pc suite 6\PcSync2.exe /NoDialog
uRun: [swg] c:\program files\google\googletoolbarnotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
uRun: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "c:\program files\common files\ahead\lib\NMBgMonitor.exe"
uRun: [L07AXLRD_23429219] "d:\microsoft student with encarta premium 2007 dvd\EDICT.EXE" -m
uRun: [Internet Download Accelerator] c:\program files\ida\ida.exe -autorun
uRun: [DAEMON Tools Lite] "c:\program files\daemon tools lite\daemon.exe" -autorun
uRun: [BitTorrent DNA] "c:\program files\dna\btdna.exe"
mRun: [SoundMan] SOUNDMAN.EXE
mRun: [nod32kui] "c:\program files\eset\nod32kui.exe" /WAITSERVICE
mRun: [PCSuiteTrayApplication] c:\progra~1\nokia\nokiap~1\LAUNCH~1.EXE -startup
mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
mRun: [RemoteControl] "c:\program files\cyberlink\powerdvd\PDVDServ.exe"
mRun: [TkBellExe] "c:\program files\common files\real\update_ob\realsched.exe" -osboot
mRun: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
mRun: [System Restore] wscript.exe "c:\windows\SysRes.vbs"
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
mRun: [Microsoft WinUpdate] c:\windows\system32\msupdte.exe
mRun: [winlogos.exe] c:\windows\winlogos.exe /s
mRun: [Huelar Services 2.0] c:\windows\system32\huelar.exe
mRun: [Microsoft Service Host] c:\documents and settings\sirvertire\start menu\programs\startup\mscvhost.exe
dRunOnce: [RunNarrator] Narrator.exe
StartupFolder: c:\docume~1\sirver~1\startm~1\programs\startup\gamesp~1.lnk - c:\program files\gamespot\GameSpotDownloadManager_Win32.exe
StartupFolder: c:\documents and settings\sirvertire\start menu\programs\startup\mscvhost.exe
StartupFolder: c:\documents and settings\sirvertire\start menu\programs\startup\PowerReg Scheduler.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\adobeg~1.lnk - c:\program files\common files\adobe\calibration\Adobe Gamma Loader.exe
uPolicies-system: DisableRegistryTools = 1 (0x1)
uPolicies-system: DisableTaskMgr = 1 (0x1)
mPolicies-explorer: NoFolderOptions = 1 (0x1)
IE: Download ALL with IDA
IE: Download with IDA
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office11\EXCEL.EXE/3000
IE: {9819CC0E-9669-4D01-9CD7-2C66DA43AC6C}
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - c:\program files\yahoo!\common\yiesrvc.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL
IE: {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - {552781AF-37E4-4FEE-920A-CED9E648EADD} - c:\program files\common files\microsoft shared\encarta search bar\ENCSBAR.DLL
LSP: c:\windows\system32\imon.dll
DPF: {149E45D8-163E-4189-86FC-45022AB2B6C9} - file:///C:/Program%20Files/Family%20Restaurant/Images/stg_drm.ocx
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://download.microsoft.com/download/5/b/0/5b0d4654-aa20-495c-b89f-c1c34c691085/LegitCheckControl.cab
DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - hxxp://ak.exe.imgfarm.com/images/nocache/funwebproducts/ei-3/ZwinkyInitialSetup1.0.1.0.cab
DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} - c:\program files\yahoo!\common\Yinsthelper.dll
DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} - hxxp://www.nvidia.com/content/DriverDownload/srl/2.0.0.1/sysreqlab2.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab
DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab
DPF: {CC450D71-CC90-424C-8638-1F2DBAC87A54} - file:///C:/Program%20Files/Diner%20Dash%202/Images/armhelper.ocx
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll

================= FIREFOX ===================

FF - ProfilePath - c:\docume~1\sirver~1\applic~1\mozilla\firefox\profiles\zib8h1yn.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.yahoo.com/search?ei=UTF-8&fr=ytff-&p=
FF - prefs.js: browser.search.selectedEngine - DAEMON Search
FF - prefs.js: browser.startup.homepage - hxxp://cm.my.yahoo.com/
FF - prefs.js: keyword.URL - hxxp://search.freecause.com/search?fr=freecause&ourmark=3&type=108&ei=utf-8&yahoo_domain=search.yahoo.com&p=
FF - component: c:\program files\daemon tools toolbar\firefoxdtt\components\DTToolbarFF.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npbittorrent.dll

============= SERVICES / DRIVERS ===============

R1 nod32drv;nod32drv;c:\windows\system32\drivers\nod32drv.sys [2008-1-14 15424]
S3 dump_wmimmc;dump_wmimmc;\??\c:\program files\amped\warrock philippines\system\gameguard\dump_wmimmc.sys --> c:\program files\amped\warrock philippines\system\gameguard\dump_wmimmc.sys [?]

=============== Created Last 30 ================

2009-03-31 09:33 93,737 a------- c:\documents and settings\sirvertire\gfx.exe
2009-03-30 21:45 <DIR> --d-h--- c:\documents and settings\sirvertire\gfx
2009-03-30 16:12 93,737 a------- c:\docume~1\alluse~1\applic~1\Apple.exe
2009-03-30 16:10 93,737 a------- C:\RECYCLER.exe
2009-03-30 16:10 93,737 a------- C:\Config.Msi.exe
2009-03-30 16:08 93,737 a------- C:\MSOCache.exe
2009-03-27 23:55 93,737 a------- c:\documents and settings\sirvertire\SendTo.exe
2009-03-27 23:55 93,737 a------- c:\documents and settings\sirvertire\restore.exe
2009-03-27 23:53 <DIR> --d-h--- c:\documents and settings\sirvertire\restore
2009-03-27 23:51 93,737 a------- C:\WINDOWS.exe
2009-03-27 23:51 93,737 a------- C:\System Volume Information.exe
2009-03-27 17:44 93,737 a------- c:\documents and settings\sirvertire\system.exe
2009-03-27 17:42 <DIR> --d-h--- c:\documents and settings\sirvertire\system
2009-03-27 17:35 93,737 a------- c:\documents and settings\sirvertire\Accessories.exe
2009-03-27 17:34 <DIR> --d-h--- c:\documents and settings\sirvertire\Accessories
2009-03-27 17:26 93,737 a------- c:\documents and settings\sirvertire\Eset.exe
2009-03-27 17:13 <DIR> --d-h--- c:\documents and settings\sirvertire\Eset
2009-03-27 16:58 93,737 a------- c:\windows\system32\oobe.exe
2009-03-27 16:57 93,737 a------- c:\windows\pchealth.exe
2009-03-27 16:56 93,737 a------- c:\windows\ie7updates.exe
2009-03-27 16:53 93,737 a------- c:\windows\$hf_mig$.exe
2009-03-27 16:53 93,737 a------- C:\Westwood.exe
2009-03-27 16:53 93,737 a------- C:\Temp.exe
2009-03-27 16:52 93,737 a------- c:\program files\Yahoo!.exe
2009-03-27 16:52 93,737 a------- c:\program files\xerox.exe
2009-03-27 16:52 93,737 a------- c:\program files\WinRAR.exe
2009-03-27 16:52 93,737 a------- c:\program files\WinMX.exe
2009-03-27 16:52 93,737 a------- c:\program files\WindowsUpdate.exe
2009-03-27 16:52 93,737 a------- c:\program files\Windows Sidebar.exe
2009-03-27 16:52 93,737 a------- c:\program files\Windows NT.exe
2009-03-27 16:52 93,737 a------- c:\program files\Windows Media Player.exe
2009-03-27 16:52 93,737 a------- c:\program files\Windows Media Connect 2.exe
2009-03-27 16:52 93,737 a------- c:\program files\VALVe.exe
2009-03-27 16:52 93,737 a------- c:\program files\Uninstall Information.exe
2009-03-27 16:52 93,737 a------- c:\program files\Trend Micro.exe
2009-03-27 16:52 93,737 a------- c:\program files\TextPad 5.exe
2009-03-27 16:52 93,737 a------- c:\program files\SystemRequirementsLab.exe
2009-03-27 16:52 93,737 a------- c:\program files\Rock Legend.exe
2009-03-27 16:52 93,737 a------- c:\program files\Real.exe
2009-03-27 16:51 93,737 a------- c:\program files\QuickTime.exe
2009-03-27 16:51 93,737 a------- c:\program files\Plant tycoon.exe
2009-03-27 16:51 93,737 a------- c:\program files\Outlook Express.exe
2009-03-27 16:51 93,737 a------- c:\program files\Online Services.exe
2009-03-27 16:51 93,737 a------- c:\program files\Nokia.exe
2009-03-27 16:51 93,737 a------- c:\program files\NetProject.exe
2009-03-27 16:51 93,737 a------- c:\program files\NetMeeting.exe
2009-03-27 16:51 93,737 a------- c:\program files\Netcom3 Cleaner.exe
2009-03-27 16:50 93,737 a------- c:\program files\Nero.exe
2009-03-27 16:50 93,737 a------- c:\program files\NCH Swift Sound.exe
2009-03-27 16:50 93,737 a------- c:\program files\NCH Software.exe
2009-03-27 16:49 93,737 a------- c:\program files\Nanny Mania 2.exe
2009-03-27 16:49 93,737 a------- c:\program files\MSXML 6.0.exe
2009-03-27 16:49 93,737 a------- c:\program files\MSXML 4.0.exe
2009-03-27 16:49 93,737 a------- c:\program files\MSN Gaming Zone.exe
2009-03-27 16:49 93,737 a------- c:\program files\MSN.exe
2009-03-27 16:49 93,737 a------- c:\program files\MSECache.exe
2009-03-27 16:49 93,737 a------- c:\program files\Mozilla Firefox.exe
2009-03-27 16:49 93,737 a------- c:\program files\Movie Maker.exe
2009-03-27 16:49 93,737 a------- c:\program files\Microsoft Student.exe
2009-03-27 16:48 93,737 a------- c:\program files\Microsoft SQL Server.exe
2009-03-27 16:48 93,737 a------- c:\program files\Microsoft Office.exe
2009-03-27 16:48 93,737 a------- c:\program files\Microsoft Games.exe
2009-03-27 16:48 93,737 a------- c:\program files\microsoft frontpage.exe
2009-03-27 16:48 93,737 a------- c:\program files\Microsoft ActiveSync.exe
2009-03-27 16:48 93,737 a------- c:\program files\Messenger.exe
2009-03-27 16:48 93,737 a------- c:\program files\Liquid Entertainment.exe
2009-03-27 16:48 93,737 a------- c:\program files\LimeWire.exe
2009-03-27 16:48 93,737 a------- c:\program files\Level Up.exe
2009-03-27 16:48 93,737 a------- c:\program files\LeeGTs Games.exe
2009-03-27 16:47 93,737 a------- c:\program files\Learning Essentials.exe
2009-03-27 16:46 93,737 a------- c:\program files\Kudos 2-in-1.exe
2009-03-27 16:46 93,737 a------- c:\program files\Java.exe
2009-03-27 16:44 93,737 a------- c:\program files\Jane's Hotel Family Hero.exe
2009-03-27 16:43 93,737 a------- c:\program files\iTunes.exe
2009-03-27 16:42 93,737 a------- c:\program files\iPod.exe
2009-03-27 16:42 93,737 a------- c:\program files\Internet Explorer.exe
2009-03-27 16:42 93,737 a------- c:\program files\InstallShield Installation Information.exe
2009-03-27 16:41 93,737 a------- c:\program files\halflife.exe
2009-03-27 16:41 93,737 a------- c:\program files\Guitar Pro 5.exe
2009-03-27 16:41 93,737 a------- c:\program files\Google.exe
2009-03-27 16:41 93,737 a------- c:\program files\GameSpy Arcade.exe
2009-03-27 16:41 93,737 a------- c:\program files\Games.exe
2009-03-27 16:41 93,737 a------- c:\program files\GameHouse.exe
2009-03-27 16:41 93,737 a------- c:\program files\Game On.exe
2009-03-27 16:41 93,737 a------- c:\program files\FunWebProducts.exe
2009-03-27 16:41 93,737 a------- c:\program files\FLV to AVI MPEG WMV 3GP MP4 iPod Converter.exe
2009-03-27 16:41 93,737 a------- c:\program files\FlashOffliner.exe
2009-03-27 16:40 93,737 a------- c:\program files\Family Restaurant.exe
2009-03-27 16:40 93,737 a------- c:\program files\ESET.exe
2009-03-27 16:40 93,737 a------- c:\program files\Enlight.exe
2009-03-27 16:39 93,737 a------- c:\program files\Electronic Arts.exe
2009-03-27 16:39 93,737 a------- c:\program files\e-Games.exe
2009-03-27 16:39 93,737 a------- c:\program files\DNA.exe
2009-03-27 16:39 93,737 a------- c:\program files\DivX.exe
2009-03-27 16:39 93,737 a------- c:\program files\directx.exe
2009-03-27 16:39 93,737 a------- c:\program files\Diner Dash Flo on the Go.exe
2009-03-27 16:39 93,737 a------- c:\program files\DIFX.exe
2009-03-27 16:39 93,737 a------- c:\program files\DAP.exe
2009-03-27 16:39 93,737 a------- c:\program files\DAEMON Tools Toolbar.exe
2009-03-27 16:39 93,737 a------- c:\program files\DAEMON Tools Lite.exe
2009-03-27 16:39 93,737 a------- c:\program files\CyberLink.exe
2009-03-27 16:39 93,737 a------- c:\program files\Cucusoft.exe
2009-03-27 16:38 93,737 a------- c:\program files\Counter-Strike 1.6.exe
2009-03-27 16:38 93,737 a------- c:\program files\Corel.exe
2009-03-27 16:38 93,737 a------- c:\program files\ComPlus Applications.exe
2009-03-27 16:38 93,737 a------- c:\program files\common files\xing shared.exe
2009-03-27 16:38 93,737 a------- c:\program files\common files\System.exe
2009-03-27 16:38 93,737 a------- c:\program files\common files\Symantec Shared.exe
2009-03-27 16:38 93,737 a------- c:\program files\common files\SpeechEngines.exe
2009-03-27 16:38 93,737 a------- c:\program files\common files\Services.exe
2009-03-27 16:38 93,737 a------- c:\program files\common files\Real.exe
2009-03-27 16:38 93,737 a------- c:\program files\common files\PCSuite.exe
2009-03-27 16:38 93,737 a------- c:\program files\common files\ODBC.exe
2009-03-27 16:38 93,737 a------- c:\program files\common files\Nokia.exe
2009-03-27 16:38 93,737 a------- c:\program files\common files\Nero.exe
2009-03-27 16:38 93,737 a------- c:\program files\common files\MSSoap.exe
2009-03-27 16:37 93,737 a------- c:\program files\common files\Microsoft Shared.exe
2009-03-27 16:37 93,737 a------- c:\program files\common files\Java.exe
2009-03-27 16:37 93,737 a------- c:\program files\common files\InstallShield.exe
2009-03-27 16:37 93,737 a------- c:\program files\common files\INCA Shared.exe
2009-03-27 16:37 93,737 a------- c:\program files\common files\EasyInfo.exe
2009-03-27 16:37 93,737 a------- c:\program files\common files\DESIGNER.exe
2009-03-27 16:37 93,737 a------- c:\program files\common files\Corel.exe
2009-03-27 16:37 93,737 a------- c:\program files\common files\Broderbund.exe
2009-03-27 16:36 93,737 a------- c:\program files\common files\Apple.exe
2009-03-27 16:36 93,737 a------- c:\program files\common files\Ahead.exe
2009-03-27 16:36 93,737 a------- c:\program files\common files\Adobe.exe
2009-03-27 16:36 93,737 a------- c:\program files\Common Files.exe
2009-03-27 16:36 93,737 a------- c:\program files\Cinema Tycoon.exe
2009-03-27 16:36 93,737 a------- c:\program files\Chikka Messenger.exe
2009-03-27 16:36 93,737 a------- c:\program files\Cake Mania 3.exe
2009-03-27 16:36 93,737 a------- c:\program files\build-a-lot 3.exe
2009-03-27 16:36 93,737 a------- c:\program files\Boris FX, Inc.exe
2009-03-27 16:36 93,737 a------- c:\program files\Bonjour.exe
2009-03-27 16:36 93,737 a------- c:\program files\BitTorrent.exe
2009-03-27 16:36 93,737 a------- c:\program files\BFG.exe
2009-03-27 16:36 93,737 a------- c:\program files\ArcSoft.exe
2009-03-27 16:36 93,737 a------- c:\program files\Apple Software Update.exe
2009-03-27 16:36 93,737 a------- c:\program files\Adobe.exe
2009-03-27 16:36 93,737 a------- C:\Program Files.exe
2009-03-27 16:36 93,737 a------- C:\OutputFolder.exe
2009-03-27 16:36 93,737 a------- C:\logs.exe
2009-03-27 16:36 93,737 a------- C:\Gphoenix-Battle Realms and Exp Winter of The Wolf.exe
2009-03-27 16:36 93,737 a------- C:\Downloads.exe
2009-03-27 16:36 93,737 a------- c:\documents and settings\sirvertire\WINDOWS.exe
2009-03-27 16:36 93,737 a------- c:\documents and settings\sirvertire\Templates.exe
2009-03-27 16:36 93,737 a------- c:\documents and settings\sirvertire\Start Menu.exe
2009-03-27 16:36 93,737 a------- c:\documents and settings\sirvertire\Recent.exe
2009-03-27 16:36 93,737 a------- c:\documents and settings\sirvertire\PrintHood.exe
2009-03-27 16:36 93,737 a------- c:\documents and settings\sirvertire\Phone Browser.exe
2009-03-27 16:36 93,737 a------- c:\documents and settings\sirvertire\NetHood.exe
2009-03-27 16:36 93,737 a------- c:\documents and settings\sirvertire\My Documents.exe
2009-03-27 16:34 93,737 a------- c:\documents and settings\sirvertire\Local Settings.exe
2009-03-27 16:34 93,737 a------- c:\documents and settings\sirvertire\Favorites.exe
2009-03-27 16:34 93,737 a------- c:\documents and settings\sirvertire\Desktop.exe
2009-03-27 16:34 93,737 a------- c:\documents and settings\sirvertire\Cookies.exe
2009-03-27 16:34 93,737 a------- c:\documents and settings\sirvertire\ChikkaDefault.exe
2009-03-27 16:34 93,737 a------- c:\docume~1\sirver~1\applic~1\Yahoo!.exe
2009-03-27 16:34 93,737 a------- c:\docume~1\sirver~1\applic~1\WinSecureAv.exe
2009-03-27 16:34 93,737 a------- c:\docume~1\sirver~1\applic~1\WinRAR.exe
2009-03-27 16:34 93,737 a------- c:\docume~1\sirver~1\applic~1\Sun.exe
2009-03-27 16:34 93,737 a------- c:\docume~1\sirver~1\applic~1\SpinTop.exe
2009-03-27 16:34 93,737 a------- c:\docume~1\sirver~1\applic~1\Sony.exe
2009-03-27 16:34 93,737 a------- c:\docume~1\sirver~1\applic~1\Sierra.exe
2009-03-27 16:34 93,737 a------- c:\docume~1\sirver~1\applic~1\SecuROM.exe
2009-03-27 16:34 93,737 a------- c:\docume~1\sirver~1\applic~1\Samsung.exe
2009-03-27 16:34 93,737 a------- c:\docume~1\sirver~1\applic~1\Recordpad.exe
2009-03-27 16:34 93,737 a------- c:\docume~1\sirver~1\applic~1\Real.exe
2009-03-27 16:34 93,737 a------- c:\docume~1\sirver~1\applic~1\Publish Providers.exe
2009-03-27 16:34 93,737 a------- c:\docume~1\sirver~1\applic~1\proDAD.exe
2009-03-27 16:34 93,737 a------- c:\docume~1\sirver~1\applic~1\PlayFirst.exe
2009-03-27 16:34 93,737 a------- c:\docume~1\sirver~1\applic~1\PC Suite.exe
2009-03-27 16:34 93,737 a------- c:\docume~1\sirver~1\applic~1\Nokia.exe
2009-03-27 16:34 93,737 a------- c:\docume~1\sirver~1\applic~1\Nokia Multimedia Player.exe
2009-03-27 16:34 93,737 a------- c:\docume~1\sirver~1\applic~1\Nero.exe
2009-03-27 16:34 93,737 a------- c:\docume~1\sirver~1\applic~1\NCH Swift Sound.exe
2009-03-27 16:34 93,737 a------- c:\docume~1\sirver~1\applic~1\Mozilla.exe
2009-03-27 16:34 93,737 a------- c:\docume~1\sirver~1\applic~1\Microsoft Games.exe
2009-03-27 16:33 93,737 a------- c:\docume~1\sirver~1\applic~1\Microsoft.exe
2009-03-27 16:32 93,737 a------- c:\docume~1\sirver~1\applic~1\Macromedia.exe
2009-03-27 16:32 93,737 a------- c:\docume~1\sirver~1\applic~1\LimeWire.exe
2009-03-27 16:32 93,737 a------- c:\docume~1\sirver~1\applic~1\Jane s Hotel Family Hero.exe
2009-03-27 16:32 93,737 a------- c:\docume~1\sirver~1\applic~1\InterTrust.exe
2009-03-27 16:32 93,737 a------- c:\docume~1\sirver~1\applic~1\Internet Download Accelerator.exe
2009-03-27 16:32 93,737 a------- c:\docume~1\sirver~1\applic~1\Identities.exe
2009-03-27 16:32 93,737 a------- c:\docume~1\sirver~1\applic~1\Helios.exe
2009-03-27 16:32 93,737 a------- c:\docume~1\sirver~1\applic~1\Google.exe
2009-03-27 16:32 93,737 a------- c:\docume~1\sirver~1\applic~1\GetRightToGo.exe
2009-03-27 16:32 93,737 a------- c:\docume~1\sirver~1\applic~1\GameHouse.exe
2009-03-27 16:32 93,737 a------- c:\docume~1\sirver~1\applic~1\DNA.exe
2009-03-27 16:32 93,737 a------- c:\docume~1\sirver~1\applic~1\DivX.exe
2009-03-27 16:32 93,737 a------- c:\docume~1\sirver~1\applic~1\Datalayer.exe
2009-03-27 16:32 93,737 a------- c:\docume~1\sirver~1\applic~1\DAEMON Tools.exe
2009-03-27 16:32 93,737 a------- c:\docume~1\sirver~1\applic~1\DAEMON Tools Pro.exe
2009-03-27 16:32 93,737 a------- c:\docume~1\sirver~1\applic~1\DAEMON Tools Lite.exe
2009-03-27 16:32 93,737 a------- c:\docume~1\sirver~1\applic~1\CyberLink.exe
2009-03-27 16:32 93,737 a------- c:\docume~1\sirver~1\applic~1\Corel.exe
2009-03-27 16:32 93,737 a------- c:\docume~1\sirver~1\applic~1\Boolat Games.exe
2009-03-27 16:32 93,737 a------- c:\docume~1\sirver~1\applic~1\BitTorrent.exe
2009-03-27 16:32 93,737 a------- c:\docume~1\sirver~1\applic~1\ArcSoft.exe
2009-03-27 16:32 93,737 a------- c:\docume~1\sirver~1\applic~1\Apple Computer.exe
2009-03-27 16:32 93,737 a------- c:\docume~1\sirver~1\applic~1\Ahead.exe
2009-03-27 16:32 93,737 a------- c:\documents and settings\sirvertire\Application Data.exe
2009-03-27 16:32 93,737 a------- c:\documents and settings\sirvertire\.SunDownloadManager.exe
2009-03-27 16:32 93,737 a------- c:\docume~1\sirver~1\applic~1\Adobe.exe
2009-03-27 16:32 93,737 a------- c:\documents and settings\all users\Templates.exe
2009-03-27 16:31 93,737 a------- c:\documents and settings\all users\Start Menu.exe
2009-03-27 16:31 93,737 a------- c:\documents and settings\all users\Favorites.exe
2009-03-27 16:31 93,737 a------- c:\documents and settings\all users\DRM.exe
2009-03-27 16:31 93,737 a------- c:\documents and settings\all users\Documents.exe
2009-03-27 16:31 93,737 a------- c:\documents and settings\all users\Desktop.exe
2009-03-27 16:31 93,737 a------- c:\documents and settings\all users\CyberLink.exe
2009-03-27 16:31 93,737 a------- c:\docume~1\alluse~1\applic~1\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}.exe
2009-03-27 16:31 93,737 a------- c:\docume~1\alluse~1\applic~1\Yahoo!.exe
2009-03-27 16:31 93,737 a------- c:\docume~1\alluse~1\applic~1\Yahoo! Companion.exe
2009-03-27 16:31 93,737 a------- c:\docume~1\alluse~1\applic~1\Windows Genuine Advantage.exe
2009-03-27 16:31 93,737 a------- c:\docume~1\alluse~1\applic~1\Trymedia.exe
2009-03-27 16:31 93,737 a------- c:\docume~1\alluse~1\applic~1\TEMP.exe
2009-03-27 16:31 93,737 a------- c:\docume~1\alluse~1\applic~1\SpeedBit.exe
2009-03-27 16:31 93,737 a------- c:\docume~1\alluse~1\applic~1\Sandlot Games.exe
2009-03-27 16:31 93,737 a------- c:\docume~1\alluse~1\applic~1\PlayFirst.exe
2009-03-27 16:31 93,737 a------- c:\docume~1\alluse~1\applic~1\Pinnacle.exe
2009-03-27 16:31 93,737 a------- c:\docume~1\alluse~1\applic~1\Pinnacle Studio Ultimate.exe
2009-03-27 16:31 93,737 a------- c:\docume~1\alluse~1\applic~1\PC Suite.exe
2009-03-27 16:31 93,737 a------- c:\docume~1\alluse~1\applic~1\Nero.exe
2009-03-27 16:31 93,737 a------- c:\docume~1\alluse~1\applic~1\NCH Swift Sound.exe
2009-03-27 16:31 93,737 a------- c:\docume~1\alluse~1\applic~1\NCH Software.exe
2009-03-27 16:31 93,737 a------- c:\docume~1\alluse~1\applic~1\n7-89-o9-3r-4t-r9.exe
2009-03-27 16:31 93,737 a------- c:\docume~1\alluse~1\applic~1\Microsoft Games.exe
2009-03-27 16:31 93,737 a------- c:\docume~1\alluse~1\applic~1\Microsoft.exe
2009-03-27 16:31 93,737 a------- c:\docume~1\alluse~1\applic~1\HipSoft.exe
2009-03-27 16:31 93,737 a------- c:\docume~1\alluse~1\applic~1\Google.exe
2009-03-27 16:31 93,737 a------- c:\docume~1\alluse~1\applic~1\Gogii.exe
2009-03-27 16:31 93,737 a------- c:\docume~1\alluse~1\applic~1\Fugazo.exe
2009-03-27 16:31 93,737 a------- c:\docume~1\alluse~1\applic~1\Downloaded Installations.exe
2009-03-27 16:31 93,737 a------- c:\docume~1\alluse~1\applic~1\DAEMON Tools Lite.exe
2009-03-27 16:31 93,737 a------- c:\docume~1\alluse~1\applic~1\CyberLink.exe
2009-03-27 16:31 93,737 a------- c:\docume~1\alluse~1\applic~1\avg8(2).exe
2009-03-27 16:31 93,737 a------- c:\docume~1\alluse~1\applic~1\Apple Computer.exe
2009-03-27 16:31 93,737 a------- c:\docume~1\alluse~1\applic~1\Ahead.exe
2009-03-27 16:31 93,737 a------- c:\windows\HuelarKiller.exe
2009-03-27 16:30 93,737 a------- c:\windows\WebJetWizard.exe
2009-03-27 16:30 93,737 a------- c:\windows\freegames2008.exe
2009-03-27 16:30 93,737 a------- c:\documents and settings\all users\Application Data.exe
2009-03-27 16:30 93,737 a------- c:\windows\mswinxpa_sp3upd.exe
2009-03-27 16:30 93,737 a------- C:\Documents and Settings.exe
2009-03-27 16:30 93,737 a------- c:\windows\Confidential_Message.exe
2009-03-27 16:30 93,737 a------- C:\divx.exe
2009-03-27 16:29 93,737 a--shr-- c:\windows\winlogos.exe
2009-03-27 16:29 93,737 a--shr-- c:\windows\system32\huelar.exe
2009-03-27 16:29 93,737 a--shr-- c:\windows\huelar.exe
2009-03-26 18:22 <DIR> --d-h--- C:\Gphoenix-Battle Realms and Exp Winter of The Wolf
2009-03-23 17:30 <DIR> --d-h--- c:\docume~1\sirver~1\applic~1\Boolat Games
2009-03-23 17:29 <DIR> --d-h--- c:\program files\Games
2009-03-23 17:29 176,128 a------- c:\windows\system32\xwr77204.dll
2009-03-23 17:29 176,128 a------- c:\windows\system32\wr77204.dll
2009-03-23 17:29 57,565,234 a------- c:\windows\system32\xa5475493.exe
2009-03-23 17:29 57,565,234 a------- c:\windows\system32\xa5466119.exe
2009-03-23 17:27 <DIR> --d-h--- c:\windows\Kudos 2-in-1
2009-03-23 17:27 <DIR> --d-h--- c:\program files\Kudos 2-in-1
2009-03-21 19:29 <DIR> --d-h--- c:\docume~1\alluse~1\applic~1\HipSoft
2009-03-21 19:24 <DIR> --d-h--- c:\program files\build-a-lot 3
2009-03-20 21:45 <DIR> --d-h--- c:\program files\WinMX
2009-03-20 12:18 <DIR> --d-h--- c:\docume~1\alluse~1\applic~1\Gogii
2009-03-20 12:16 <DIR> --d-h--- c:\windows\Nanny Mania 2
2009-03-20 12:16 <DIR> --d-h--- c:\program files\Nanny Mania 2
2009-03-19 15:44 <DIR> --d-h--- c:\program files\GameHouse
2009-03-18 11:07 <DIR> --d-h--- c:\program files\Cinema Tycoon
2009-03-18 10:04 876 a------- c:\windows\$_hpcst$.hpc
2009-03-18 10:00 86,016 a------- c:\windows\unvise32.exe
2009-03-18 10:00 <DIR> --d-h--- c:\program files\common files\Broderbund
2009-03-18 10:00 <DIR> --d-h--- c:\program files\Game On
2009-03-16 22:12 <DIR> --d-h--- c:\program files\Family Restaurant
2009-03-16 15:04 <DIR> --d-h--- c:\program files\Plant tycoon
2009-03-16 15:03 <DIR> --d-h--- c:\program files\Cake Mania 3
2009-03-16 07:36 <DIR> --d-h--- c:\program files\Diner Dash Flo on the Go
2009-03-16 07:36 <DIR> --d-h--- c:\program files\BFG
2009-03-15 17:24 <DIR> --d-h--- c:\docume~1\sirver~1\applic~1\Jane s Hotel Family Hero
2009-03-15 17:23 <DIR> --d-h--- c:\program files\Jane's Hotel Family Hero
2009-03-15 17:22 5,119 a------- c:\windows\system32\msupdte.exe
2009-03-15 12:56 4,096 a------- c:\windows\d3dx.dat
2009-03-15 12:53 <DIR> --d-h--- c:\program files\Rock Legend
2009-03-15 11:59 <DIR> --d-h--- c:\windows\Cinema Tycoon 2 Movie Mania
2009-03-12 19:58 <DIR> --d-h--- c:\docume~1\alluse~1\applic~1\Sandlot Games
2009-03-05 16:06 92,467,306 a------- c:\windows\system32\xa3974404.exe
2009-03-05 16:06 92,467,306 a------- c:\windows\system32\xa3959703.exe

==================== Find3M ====================

2009-02-28 08:25 92,467,306 a------- c:\windows\system32\xa3834393.exe
2009-02-28 08:25 92,467,306 a------- c:\windows\system32\xa3812672.exe
2009-02-09 18:19 1,846,272 -------- c:\windows\system32\win32k.sys
2009-01-31 09:54 262,144 a------- c:\windows\system32\wrap_oal.dll
2009-01-31 09:54 86,016 a------- c:\windows\system32\OpenAL32.dll
2009-01-12 12:45 107,888 -------- c:\windows\system32\CmdLineExt.dll
2008-05-05 19:53 93,737 a------- c:\windows\inf\iem\0409.exe
2008-05-05 19:53 93,737 a------- c:\windows\inf\IEM.exe
2008-03-16 02:26 5,812 a------- c:\program files\install.log
2008-05-05 19:53 93,737 a--shr-- c:\windows\huelar.exe
2008-05-05 19:53 93,737 a--shr-- c:\windows\winlogos.exe
2008-05-05 19:53 93,737 a--shr-- c:\windows\system32\huelar.exe

============= FINISH: 9:35:37.06 ===============

Attached Files



BC AdBot (Login to Remove)

 


#2 miekiemoes

miekiemoes

    Malware Killer Dog


  • Malware Response Team
  • 19,420 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:Belgium
  • Local time:09:19 AM

Posted 31 March 2009 - 02:32 AM

Hi,

Your computer is EXTREMELY infected!

I would love to have some samples first - just some random ones of the folders it created, so, * Please download the Suspicious File Packer from here:
http://www.safer-networking.org/files/sfp.zip
Unzip it to the desktop and run it.

Paste the following bold part into the Suspicious File Packer window:

c:\program files\Windows Media Player.exe
c:\program files\xerox.exe
C:\WINDOWS.exe


Allow SFP to pack the file. This will generate a CAB archive on your desktop.
Go to this page.
Enter the url of this thread in the first field.
Where it says, browse to the file that you want to submit, click the browse button next to the second field and browse to the CAB archive that was been created on your desktop.
The cab file will be called requested-files[*].cab (the * stands for the date and hour).
Then click the Send File button below.

Let me know once you've uploaded it.
AntispywareScanners---Antivirus Scanners---Firewalls---Online Scanners---Prevention---Help! My computer is slow---My Blog---Follow me on Twitter.
My help is ALWAYS FREE, but if you want to donate to help me continue my fight against malware -- click here!
Asking for help via Private Message or Mail will be ignored - So If you need help, post your problem in the forum.

#3 miekiemoes

miekiemoes

    Malware Killer Dog


  • Malware Response Team
  • 19,420 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:Belgium
  • Local time:09:19 AM

Posted 01 April 2009 - 04:14 AM

Hi,

Is this you who send me the files?

Anyway, uninstall your ESET antivirus and reboot.

After reboot, * Please install Avira Antivirus: http://www.free-av.com/

Perform a full scan with Avira and let it delete everything it is finding.
Then reboot.
After reboot, open your Avira and select "reports".
There doubleclick the report from the Full scan you have done. Click the "Report File" button and copy and paste this report in your next reply together with a new DDS log.
AntispywareScanners---Antivirus Scanners---Firewalls---Online Scanners---Prevention---Help! My computer is slow---My Blog---Follow me on Twitter.
My help is ALWAYS FREE, but if you want to donate to help me continue my fight against malware -- click here!
Asking for help via Private Message or Mail will be ignored - So If you need help, post your problem in the forum.

#4 miekiemoes

miekiemoes

    Malware Killer Dog


  • Malware Response Team
  • 19,420 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:Belgium
  • Local time:09:19 AM

Posted 16 April 2009 - 07:14 AM

Due to the lack of feedback, this Topic is closed.
If you need this topic reopened for continuations of existing problems, please request this by sending me a PM with the address of the thread. This applies only to the original topic starter.

Everyone else please begin a New Topic.
AntispywareScanners---Antivirus Scanners---Firewalls---Online Scanners---Prevention---Help! My computer is slow---My Blog---Follow me on Twitter.
My help is ALWAYS FREE, but if you want to donate to help me continue my fight against malware -- click here!
Asking for help via Private Message or Mail will be ignored - So If you need help, post your problem in the forum.




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users