Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

usb problems, also winsetup66.exe


  • This topic is locked This topic is locked
3 replies to this topic

#1 gogofletch

gogofletch

  • Members
  • 5 posts
  • OFFLINE
  •  
  • Local time:06:54 AM

Posted 17 April 2009 - 06:19 PM

I reinstalled windows xp and I was installing software and drivers and now I have two problems.

1) my usb won't mount. I tried reinstalling drivers but still the same thing. It recognizes the drive, installs the drivers and says it is working correctly but does not assign it a drive letter so I can't use it or see it's contents.

2) when surfing the internet I constantly get re-directed to yellowcom.address.com, and others that are similar. Also Avast keeps blocking a "malicious site" something like caught-you/.../winsetup66.exe. While I was investigating I found in my registry a key pointing to winsetup66.exe in a search assistant folder, after deleting every trace I could find of that i rebooted and found everything back intact the way it was before I deleted it. Ad-aware and spybot found things, but after the scans I am still having problems.

dds.txt...


DDS (Ver_09-03-16.01) - NTFSx86
Run by Andrew at 17:06:43.98 on Fri 04/17/2009
Internet Explorer: 8.0.6001.18702
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.894.288 [GMT -6:00]

AV: avast! antivirus 4.8.1335 [VPS 090417-0] *On-access scanning enabled* (Updated)

============== Running Processes ===============

C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
svchost.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
C:\Program Files\NETGEAR\WN511T\WN511T.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Orbitdownloader\orbitdm.exe
C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
C:\Program Files\Orbitdownloader\orbitnet.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\MediaCoder\MediaCoder.exe
C:\Documents and Settings\Andrew\Desktop\dds.scr

============== Pseudo HJT Report ===============

uSearch Page = hxxp://www.google.com
uSearch Bar = hxxp://www.google.com/ie
uDefault_Search_URL = hxxp://www.google.com/ie
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
BHO: c:\windows\system32\jh9fgo4ksdgf.dll: {d7bf4552-94f1-42bd-f434-3604812c856d} - c:\windows\system32\jh9fgo4ksdgf.dll
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [SpybotSD TeaTimer] c:\program files\spybot - search & destroy\TeaTimer.exe
mRun: [avast!] c:\progra~1\alwils~1\avast4\ashDisp.exe
mRun: [ATIPTA] "c:\program files\ati technologies\ati control panel\atiptaxx.exe"
mRun: [Ad-Watch] c:\program files\lavasoft\ad-aware\AAWTray.exe
mRun: [WN511T.exe] c:\program files\netgear\wn511t\WN511T.exe
dRun: [<NO NAME>] c:\windows\temp\r8ele04v5m.exe
dRun: [Windows Resurections] c:\windows\temp\r8ele04v5m.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\orbit.lnk - c:\program files\orbitdownloader\orbitdm.exe
IE: &Download by Orbit - c:\program files\orbitdownloader\orbitmxt.dll/201
IE: &Grab video by Orbit - c:\program files\orbitdownloader\orbitmxt.dll/204
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: Do&wnload selected by Orbit - c:\program files\orbitdownloader\orbitmxt.dll/203
IE: Down&load all by Orbit - c:\program files\orbitdownloader\orbitmxt.dll/202
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office11\EXCEL.EXE/3000
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\program files\spybot - search & destroy\SDHelper.dll
DPF: {C7DB51B4-BCF7-4923-8874-7F1A0DC92277} - hxxp://office.microsoft.com/officeupdate/content/opuc4.cab
Notify: AtiExtEvent - Ati2evxx.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
STS: c:\windows\system32\jh9fgo4ksdgf.dll: {d7bf4552-94f1-42bd-f434-3604812c856d} - c:\windows\system32\jh9fgo4ksdgf.dll

================= FIREFOX ===================

FF - ProfilePath - c:\docume~1\andrew\applic~1\mozilla\firefox\profiles\i56pnjia.default\
FF - prefs.js: browser.startup.homepage - www.google.com
FF - plugin: c:\program files\google\picasa3\npPicasa3.dll
FF - plugin: c:\program files\k-lite codec pack\real\browser\plugins\nppl3260.dll
FF - plugin: c:\program files\k-lite codec pack\real\browser\plugins\nprpjplug.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npbittorrent.dll

============= SERVICES / DRIVERS ===============

R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [2009-4-16 64160]
R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2009-4-15 114768]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2009-4-15 20560]
R2 avast! Antivirus;avast! Antivirus;c:\program files\alwil software\avast4\ashServ.exe [2009-4-15 138680]
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\lavasoft\ad-aware\AAWService.exe [2009-3-9 951632]
R3 avast! Mail Scanner;avast! Mail Scanner;c:\program files\alwil software\avast4\ashMaiSv.exe [2009-4-15 254040]
R3 avast! Web Scanner;avast! Web Scanner;c:\program files\alwil software\avast4\ashWebSv.exe [2009-4-15 352920]
R3 CrystalSysInfo;CrystalSysInfo;c:\program files\mediacoder\SysInfo.sys [2007-9-25 15152]
R3 HSFHWATI;HSFHWATI;c:\windows\system32\drivers\HSFHWATI.sys [2005-8-23 231424]
R3 NETMW145;Marvell TOPDOG ™ 802.11n Driver for Windows XP;c:\windows\system32\drivers\NETMW145.sys [2009-4-17 722560]
S1 vcdrom;Virtual CD-ROM Device Driver;\??\c:\windows\system32\drivers\vcdrom.sys --> c:\windows\system32\drivers\VCdRom.sys [?]

=============== Created Last 30 ================

2009-04-17 14:34 <DIR> --d----- c:\docume~1\andrew\applic~1\Broad Intelligence
2009-04-17 13:38 <DIR> --d----- c:\windows\system32\KB905474
2009-04-17 12:11 722,560 a------- c:\windows\system32\drivers\NETMW145.sys
2009-04-17 12:11 94,208 a------- c:\windows\system32\GTW32N50.dll
2009-04-17 12:10 31,930 a------- c:\windows\system32\GTNDIS3.VXD
2009-04-17 12:10 15,872 a------- c:\windows\system32\GTNDIS5.sys
2009-04-17 12:10 <DIR> --d----- c:\program files\NETGEAR
2009-04-17 01:02 <DIR> --d----- c:\windows\system32\scripting
2009-04-17 01:02 <DIR> --d----- c:\windows\l2schemas
2009-04-17 01:02 <DIR> --d----- c:\windows\system32\en
2009-04-17 01:02 <DIR> --d----- c:\windows\system32\bits
2009-04-17 00:58 <DIR> --d----- c:\program files\Spybot - Search & Destroy
2009-04-17 00:58 <DIR> --d----- c:\docume~1\alluse~1\applic~1\Spybot - Search & Destroy
2009-04-17 00:54 <DIR> --d----- c:\windows\ServicePackFiles
2009-04-17 00:49 9,200 -------- c:\windows\system32\drivers\cdralw2k.sys
2009-04-17 00:49 9,072 -------- c:\windows\system32\drivers\cdr4_xp.sys
2009-04-17 00:48 <DIR> --d----- c:\windows\network diagnostic
2009-04-17 00:48 <DIR> --d----- c:\windows\system32\IOSUBSYS
2009-04-17 00:23 15,688 a------- c:\windows\system32\lsdelete.exe
2009-04-17 00:15 95,424 -------- c:\windows\system32\drivers\slnthal.sys
2009-04-17 00:14 180,360 -------- c:\windows\system32\drivers\ntmtlfax.sys
2009-04-17 00:13 106,496 -------- c:\windows\system32\mmcfxcommon.dll
2009-04-17 00:13 33,792 -------- c:\windows\system32\mmcperf.exe
2009-04-17 00:13 397,312 -------- c:\windows\system32\mmcex.dll
2009-04-17 00:13 184,320 -------- c:\windows\system32\microsoft.managementconsole.dll
2009-04-17 00:13 37,376 -------- c:\windows\system32\l2gpstore.dll
2009-04-17 00:13 61,440 -------- c:\windows\system32\kmsvc.dll
2009-04-17 00:13 6,144 -------- c:\windows\system32\kbdpash.dll
2009-04-17 00:13 6,144 -------- c:\windows\system32\kbdnepr.dll
2009-04-17 00:13 6,144 -------- c:\windows\system32\kbdiultn.dll
2009-04-17 00:13 6,144 -------- c:\windows\system32\kbdbhc.dll
2009-04-17 00:11 12,800 -------- c:\windows\system32\credssp.dll
2009-04-16 23:59 64,160 a------- c:\windows\system32\drivers\Lbd.sys
2009-04-16 23:47 <DIR> -cd-h--- c:\docume~1\alluse~1\applic~1\{7972B2E5-3E09-4E5E-81B7-FE5819D6772F}
2009-04-16 23:47 <DIR> --d----- c:\program files\Lavasoft
2009-04-16 22:42 111,616 a------- c:\windows\system32\Ltih30tb.dll
2009-04-16 22:42 <DIR> --d----- c:\program files\WexTech
2009-04-16 22:42 <DIR> --d----- c:\program files\common files\WexTech Shared
2009-04-16 22:42 <DIR> --d----- c:\program files\common files\LHSPF
2009-04-16 22:42 304,128 a------- c:\windows\IsUninst.exe
2009-04-16 22:40 <DIR> --d----- c:\documents and settings\andrew\WINDOWS
2009-04-16 22:40 553 a------- c:\windows\system32\mapisvc.inf
2009-04-16 22:37 123,392 -------- c:\windows\system32\dzip32.dll
2009-04-16 22:37 60,928 -------- c:\windows\system32\sfxbe322.dll
2009-04-16 22:37 60,416 -------- c:\windows\system32\sfxbe321.dll
2009-04-16 22:37 54,272 -------- c:\windows\system32\sfxfe32.exe
2009-04-16 22:37 204,800 -------- c:\windows\system32\adfactry.dll
2009-04-16 22:37 96,768 -------- c:\windows\system32\dunzip32.dll
2009-04-16 22:37 14,848 -------- c:\windows\system32\adreg32.exe
2009-04-16 22:37 417,792 -------- c:\windows\system32\fxdb.dll
2009-04-16 22:37 122,880 -------- c:\windows\system32\FXAB32.DLL
2009-04-16 22:35 <DIR> --d----- c:\program files\Corel
2009-04-16 22:34 <DIR> --d----- c:\windows\Corel
2009-04-16 22:23 <DIR> --dsh--- c:\documents and settings\andrew\PrivacIE
2009-04-16 22:21 376 a------- c:\windows\ODBC.INI
2009-04-16 22:21 17,920 a------- c:\windows\system32\mdimon.dll
2009-04-16 22:20 <DIR> --d----- c:\program files\Microsoft ActiveSync
2009-04-16 22:19 <DIR> --d----- c:\windows\SHELLNEW
2009-04-16 20:29 <DIR> --d----- c:\windows\pss
2009-04-16 14:03 46 a------- c:\windows\system32\p2hhr.bat
2009-04-16 14:03 15,000 a------- c:\windows\system32\jh9fgo4ksdgf.dll
2009-04-16 14:03 23,040 a------- c:\windows\system32\ak1.exe
2009-04-16 13:20 <DIR> --d----- c:\docume~1\alluse~1\applic~1\DAEMON Tools Pro
2009-04-16 13:20 <DIR> --d----- c:\program files\DAEMON Tools Pro
2009-04-16 13:17 717,296 a------- c:\windows\system32\drivers\sptd.sys
2009-04-16 13:17 <DIR> --d----- c:\docume~1\andrew\applic~1\DAEMON Tools Pro
2009-04-16 12:59 <DIR> --d----- c:\program files\Windows Media Connect 2
2009-04-16 12:57 <DIR> --d----- c:\windows\system32\LogFiles
2009-04-16 12:26 <DIR> --d----- c:\program files\WirelessMon
2009-04-15 17:46 2,560 -------- c:\windows\system32\xpsp4res.dll
2009-04-15 17:46 215,552 -c------ c:\windows\system32\dllcache\wordpad.exe
2009-04-15 17:45 272,128 -c------ c:\windows\system32\dllcache\bthport.sys
2009-04-15 17:45 272,128 -------- c:\windows\system32\drivers\bthport.sys
2009-04-15 17:15 0 a---h--- c:\windows\system32\drivers\Msft_Kernel_HpqKbFiltr_01005.Wdf
2009-04-15 17:15 0 a---h--- c:\windows\system32\drivers\MsftWdf_Kernel_01005_Coinstaller_Critical.Wdf
2009-04-15 17:14 1,560,576 a------- c:\windows\system32\BttnCmns_64.dll
2009-04-15 17:14 1,560,576 a------- c:\windows\system32\BttnCmns.dll
2009-04-15 17:14 1,419,232 a------- c:\windows\system32\wdfcoinstaller01005.dll
2009-04-15 17:14 987,136 a------- c:\windows\system32\BttnCmn.dll
2009-04-15 17:14 16,768 a------- c:\windows\system32\drivers\HpqKbFiltr.sys
2009-04-15 17:13 <DIR> --d----- c:\windows\system32\ReinstallBackups
2009-04-15 17:12 <DIR> --d----- c:\program files\ATI Technologies
2009-04-15 17:10 <DIR> --d----- c:\program files\K-Lite Codec Pack
2009-04-15 16:59 <DIR> --d----- c:\program files\MediaCoder
2009-04-15 16:59 6,272 a------- c:\windows\system32\drivers\splitter.sys
2009-04-15 16:58 52,864 a------- c:\windows\system32\drivers\dmusic.sys
2009-04-15 16:58 7,552 a------- c:\windows\system32\drivers\mskssrv.sys
2009-04-15 16:58 4,992 a------- c:\windows\system32\drivers\mspqm.sys
2009-04-15 16:58 5,376 a------- c:\windows\system32\drivers\mspclock.sys
2009-04-15 16:58 <DIR> --d----- c:\program files\CONEXANT
2009-04-15 16:58 4,096 a------- c:\windows\system32\ksuser.dll
2009-04-15 16:58 129,536 a------- c:\windows\system32\ksproxy.ax
2009-04-15 16:51 <DIR> --d----- c:\windows\system32\Adobe
2009-04-15 16:44 <DIR> --d----- c:\windows\ie8updates
2009-04-15 16:41 <DIR> -cd-h--- c:\windows\ie8
2009-04-15 16:37 105,984 -c------ c:\windows\system32\dllcache\iecompat.dll
2009-04-15 16:30 <DIR> --d----- c:\windows\system32\PreInstall
2009-04-15 16:30 26,144 a------- c:\windows\system32\spupdsvc.exe
2009-04-15 16:05 8,461,312 -c------ c:\windows\system32\dllcache\shell32.dll
2009-04-15 16:02 361,600 -c------ c:\windows\system32\dllcache\tcpip.sys
2009-04-15 16:02 245,248 -c------ c:\windows\system32\dllcache\mswsock.dll
2009-04-15 16:02 225,856 -c------ c:\windows\system32\dllcache\tcpip6.sys
2009-04-15 16:02 147,968 -c------ c:\windows\system32\dllcache\dnsapi.dll
2009-04-15 16:02 138,496 -c------ c:\windows\system32\dllcache\afd.sys
2009-04-15 15:29 3,366,912 a------- c:\windows\system32\GPhotos.scr
2009-04-15 14:50 <DIR> --d----- c:\program files\WinISO53
2009-04-15 14:48 <DIR> --d----- c:\docume~1\andrew\applic~1\BitTorrent
2009-04-15 14:48 <DIR> --d----- c:\program files\DNA
2009-04-15 14:48 <DIR> --d----- c:\program files\BitTorrent
2009-04-15 14:48 <DIR> --d----- c:\docume~1\andrew\applic~1\DNA
2009-04-15 13:45 12,928 a------- c:\windows\system32\drivers\filedisk.sys
2009-04-15 12:31 1,060,864 a------- c:\windows\system32\MFC71.dll
2009-04-15 12:31 499,712 a------- c:\windows\system32\MSVCP71.dll
2009-04-15 12:31 348,160 a------- c:\windows\system32\MSVCR71.dll
2009-04-15 05:45 938,045,440 a------- c:\windows\MEMORY.DMP
2009-04-15 05:03 16,896 ac------ c:\windows\system32\dllcache\status.dll
2009-04-15 05:02 9,216 ac------ c:\windows\system32\dllcache\kbdnecat.dll
2009-04-15 05:01 480,256 ac------ c:\windows\system32\dllcache\cintsetp.exe
2009-04-15 04:59 488 a---hr-- c:\windows\system32\logonui.exe.manifest
2009-04-15 04:59 749 a---hr-- c:\windows\WindowsShell.Manifest
2009-04-15 04:59 749 a---hr-- c:\windows\system32\wuaucpl.cpl.manifest
2009-04-15 04:59 749 a---hr-- c:\windows\system32\sapi.cpl.manifest
2009-04-15 04:59 749 a---hr-- c:\windows\system32\nwc.cpl.manifest
2009-04-15 04:59 749 a---hr-- c:\windows\system32\ncpa.cpl.manifest
2009-04-15 04:52 20,992 a------- c:\windows\system32\drivers\RTL8139.sys
2009-04-15 04:07 <DIR> --d----- c:\windows\system32\NtmsData
2009-04-14 21:30 <DIR> --d----- c:\documents and settings\andrew\editxp
2009-04-14 21:16 <DIR> --d----- c:\windows\cabsdk
2009-04-14 21:16 <DIR> --d----- c:\program files\ISO Recorder
2009-04-14 20:58 <DIR> --d----- C:\Downloads
2009-04-14 20:58 <DIR> --d----- c:\program files\Orbitdownloader
2009-04-14 20:42 <DIR> --d----- c:\windows\system32\SoftwareDistribution
2009-04-14 20:41 <DIR> --dsh--- c:\documents and settings\andrew\UserData
2009-04-14 20:41 13,676 a------- c:\windows\system32\wpa.bak
2009-04-14 15:26 <DIR> --d----- C:\test
2009-04-14 14:58 176,128 a------- c:\windows\system32\bcmwlu00.EXE
2009-04-14 14:58 429,184 a------- c:\windows\system32\drivers\BCMWL5.SYS
2009-04-14 14:58 <DIR> --d----- C:\SWSetup
2009-04-14 14:53 <DIR> --d----- c:\documents and settings\Andrew
2009-04-14 14:48 <DIR> --ds---- c:\windows\system32\Microsoft
2009-04-14 14:47 8,192 a------- c:\windows\REGLOCS.OLD
2009-04-14 14:43 <DIR> --d----- c:\windows\system32\xircom
2009-04-14 14:41 <DIR> --dsh--- c:\documents and settings\all users\DRM
2009-04-14 14:41 488 a---hr-- c:\windows\system32\WindowsLogon.manifest
2009-04-14 14:41 <DIR> --ds---- c:\windows\Downloaded Program Files
2009-04-14 14:41 <DIR> --d--r-- c:\windows\Offline Web Pages
2009-04-14 14:40 749 a---hr-- c:\windows\system32\cdplayer.exe.manifest
2009-04-14 14:40 <DIR> --d-h--- c:\program files\WindowsUpdate
2009-04-14 14:40 4,399,505 ac------ c:\windows\system32\dllcache\nls302en.lex
2009-04-14 14:40 <DIR> --d----- c:\windows\system32\DirectX
2009-04-14 14:40 99,840 ac------ c:\windows\system32\dllcache\helphost.exe
2009-04-14 14:40 35,328 ac------ c:\windows\system32\dllcache\notiflag.exe
2009-04-14 14:40 21,504 ac------ c:\windows\system32\dllcache\brpinfo.dll
2009-04-14 14:40 11,264 ac------ c:\windows\system32\dllcache\atrace.dll
2009-04-14 14:40 6,656 ac------ c:\windows\system32\dllcache\hcappres.dll
2009-04-14 14:40 11,264 a------- c:\windows\system32\atrace.dll
2009-04-14 14:39 <DIR> --d----- c:\program files\common files\MSSoap
2009-04-14 14:37 <DIR> --d----- c:\program files\Online Services
2009-04-14 14:37 <DIR> --d----- c:\program files\Messenger
2009-04-14 14:37 <DIR> --d----- c:\program files\MSN Gaming Zone
2009-04-14 14:37 <DIR> --d----- c:\program files\Windows NT
2009-04-14 07:26 <DIR> --d----- c:\program files\common files\ODBC
2009-04-14 07:26 <DIR> --d----- c:\program files\common files\SpeechEngines
2009-04-14 07:26 <DIR> --d--r-- c:\documents and settings\all users\Documents

==================== Find3M ====================

2009-04-17 01:07 86,327 a------- c:\windows\pchealth\helpctr\offlinecache\index.dat
2009-04-15 04:58 22,704 a------- c:\windows\system32\emptyregdb.dat
2009-03-16 18:42 524,288 a------- c:\windows\opuc.dll
2009-03-08 05:34 914,944 a------- c:\windows\system32\wininet.dll
2009-03-08 05:34 43,008 a------- c:\windows\system32\licmgr10.dll
2009-03-08 05:33 18,944 a------- c:\windows\system32\corpol.dll
2009-03-08 05:33 420,352 a------- c:\windows\system32\vbscript.dll
2009-03-08 05:32 72,704 a------- c:\windows\system32\admparse.dll
2009-03-08 05:32 71,680 a------- c:\windows\system32\iesetup.dll
2009-03-08 05:31 34,816 a------- c:\windows\system32\imgutil.dll
2009-03-08 05:31 48,128 a------- c:\windows\system32\mshtmler.dll
2009-03-08 05:31 45,568 a------- c:\windows\system32\mshta.exe
2009-03-08 05:22 156,160 a------- c:\windows\system32\msls31.dll
2009-03-06 08:22 284,160 a------- c:\windows\system32\pdh.dll
2009-03-02 12:10 67,584 a------- c:\windows\system32\ff_vfw.dll
2009-02-09 06:10 729,088 a------- c:\windows\system32\lsasrv.dll
2009-02-09 06:10 714,752 a------- c:\windows\system32\ntdll.dll
2009-02-09 06:10 617,472 a------- c:\windows\system32\advapi32.dll
2009-02-09 06:10 401,408 a------- c:\windows\system32\rpcss.dll
2009-02-09 05:13 1,846,784 a------- c:\windows\system32\win32k.sys
2009-02-07 19:02 2,066,048 a------- c:\windows\system32\ntkrnlpa.exe
2009-02-06 05:11 110,592 a------- c:\windows\system32\services.exe
2009-02-06 05:08 2,189,056 a------- c:\windows\system32\ntoskrnl.exe
2009-02-06 04:39 35,328 a------- c:\windows\system32\sc.exe
2009-02-03 13:59 56,832 a------- c:\windows\system32\secur32.dll

============= FINISH: 17:07:27.93 ===============


Thanks in advance!

Attached Files



BC AdBot (Login to Remove)

 


#2 gogofletch

gogofletch
  • Topic Starter

  • Members
  • 5 posts
  • OFFLINE
  •  
  • Local time:06:54 AM

Posted 20 April 2009 - 02:05 PM

please help me...

#3 fenzodahl512

fenzodahl512

  • Members
  • 6,738 posts
  • OFFLINE
  •  
  • Local time:08:54 PM

Posted 28 April 2009 - 02:07 AM

Hello, my name is fenzodahl512 and welcome to Bleeping Computer.. Please do the following....



Please download The Comedian.exe to your desktop
  • Double click the program to run it. It will only take around several minutes to run.
  • It will do a series of tasks and tell you when each one is finished.
  • You will be prompted to press any key after each step
  • When it is done it will close and exit itself automatically.
  • You can delete The_Comedian.exe once it is finished



NEXT


Please download Malwarebytes' Anti-Malware from HERE or HERE

Note: If you already have Malwarebytes' Anti-Malware, just run and update it.. Then do a "Perform Full Scan"

Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Full Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.
Extra Note:
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediately.




NEXT


Please download RSIT by random/random and save it to your Desktop.
  • Double click on RSIT.exe to run RSIT
  • Before you click "Continue", make sure you change the List files/folders created or modified in the last 3 months
  • Click Continue at the disclaimer screen.
  • Once it has finished, two logs will open. Please post the contents of both log.txt and info.txt in your next reply.



NEXT


Please download GMER and unzip it to your Desktop. <<mirror>>
If you see "random" name, just leave it.. If you see "GMER", please rename GMER into GAMERS
  • Open the renamed program and click on the Rootkit tab.
  • Make sure all the boxes on the right of the screen are checked, EXCEPT for ‘Show All’.
  • Click on Scan.
  • When the scan has run click Copy and paste the results into a Notepad >> save it and attach in this thread.
IMPORTANT: Do NOT run any program while you are doing these scans as it may interfere with the output results



Post me these logs in your next reply.. Post each log in separate post..

1. Malwarebytes'
2. RSIT log.txt
3. RSIT info.txt
4. Attach GMER result..

Keep calm, make it simple, use your brain, don't freak out, and you'll be just fine..
Awesomeness: When I get sad, I stop being sad and be awesome instead.. True story - Barney Stinson
Posted Image Posted Image
Its gonna be legen.. wait for it.. dary! Cherish the pain, it means you're still alive


#4 fenzodahl512

fenzodahl512

  • Members
  • 6,738 posts
  • OFFLINE
  •  
  • Local time:08:54 PM

Posted 03 May 2009 - 05:46 PM

Due to the lack of feedback this Topic is closed.

If you need this topic reopened, please request this by sending the moderating team a PM with the address of the thread. This applies only to the original topic starter.

Everyone else please begin a New Topic

Keep calm, make it simple, use your brain, don't freak out, and you'll be just fine..
Awesomeness: When I get sad, I stop being sad and be awesome instead.. True story - Barney Stinson
Posted Image Posted Image
Its gonna be legen.. wait for it.. dary! Cherish the pain, it means you're still alive





0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users