Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Unknown Infection


  • This topic is locked This topic is locked
3 replies to this topic

#1 Wadey

Wadey

  • Members
  • 10 posts
  • OFFLINE
  •  
  • Local time:04:15 PM

Posted 18 June 2009 - 12:23 PM

Referred here from: http://www.bleepingcomputer.com/forums/t/234809/programs-and-anti-virusspyware-keep-closing/ ~ OB

Hi,

As requested by SuperBird here is the DDS log.
The file "attach" is also attached.
Attached File  Attach.txt   24.44KB   11 downloads

DDS (Ver_09-05-14.01) - NTFSx86
Run by Keith Wright at 18:13:21.46 on Thu 06/18/2009
Internet Explorer: 8.0.6001.18702
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.503.281 [GMT 1:00]

AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
AV: avast! antivirus 4.8.1335 [VPS 090617-0] *On-access scanning enabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}

============== Running Processes ===============

C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
C:\Program Files\Intel\Wireless\Bin\ZcfgSvc.exe
C:\WINDOWS\Explorer.EXE
svchost.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\PROGRA~1\Intel\Wireless\Bin\1XConfig.exe
C:\WINDOWS\system32\spoolsv.exe
svchost.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\Program Files\AVG\AVG8\avgcsrvx.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\stsystra.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\System32\svchost.exe -k HTTPFilter
F:\Tools\HJT\dds.scr

============== Pseudo HJT Report ===============

uSearch Page = hxxp://www.google.com
uSearch Bar = hxxp://www.google.com/ie
mSearch Bar = hxxp://uk.red.clientapps.yahoo.com/customize/btyahoo/defaults/sb/*http://uk.docs.yahoo.com/info/bt_side.html
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/keyword/%s
mSearchAssistant = hxxp://www.google.com/ie
uURLSearchHooks: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn\yt.dll
BHO: Yahoo! Toolbar Helper: {02478d38-c3f9-4efb-9b51-7695eca05670} - c:\program files\yahoo!\companion\installs\cpn\yt.dll
BHO: AcroIEHlprObj Class: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 6.0\reader\activex\AcroIEHelper.dll
BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg8\avgssie.dll
BHO: Yahoo! IE Services Button: {5bab4b5b-68bc-4b02-94d6-2fc0de4a7897} - c:\progra~1\yahoo!\common\yiesrvc.dll
BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO: DriveLetterAccess: {5ca3d70e-1895-11cf-8e15-001234567890} - c:\windows\system32\dla\tfswshx.dll
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: SidebarAutoLaunch Class: {f2aa9440-6328-4933-b7c9-a6ccdf9cbf6d} - c:\program files\yahoo!\browser\YSidebarIEBHO.dll
TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn\yt.dll
TB: {0B53EAC3-8D69-4B9E-9B19-A37C9A5676A7} - No File
TB: {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - No File
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe
mRun: []
mRun: [IntelWireless] c:\program files\intel\wireless\bin\ifrmewrk.exe /tf Intel PROSet/Wireless
mRun: [dla] c:\windows\system32\dla\tfswctrl.exe
mRun: [ISUSPM Startup] c:\progra~1\common~1\instal~1\update~1\ISUSPM.exe -startup
mRun: [ISUSScheduler] "c:\program files\common files\installshield\updateservice\issch.exe" -start
mRun: [igfxtray] c:\windows\system32\igfxtray.exe
mRun: [igfxhkcmd] c:\windows\system32\hkcmd.exe
mRun: [igfxpers] c:\windows\system32\igfxpers.exe
mRun: [SigmatelSysTrayApp] stsystra.exe
mRun: [avast!] c:\progra~1\alwils~1\avast4\ashDisp.exe
mRun: [AVG8_TRAY] c:\progra~1\avg\avg8\avgtray.exe
mRunOnce: [Malwarebytes' Anti-Malware] c:\program files\malwarebytes' anti-malware\mbamgui.exe /install /silent
dRun: [CTFMON.EXE] c:\windows\system32\CTFMON.EXE
dRunOnce: [RunNarrator] Narrator.exe
dRunOnce: [Magnify] Magnify.exe
dRunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe
IE: &Search - ?p=ZN
IE: {77E68763-4284-41d6-B7E7-B6E1F053A9E7} - c:\program files\empirepokermaster\empirepoker\RunEPoker.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - c:\progra~1\yahoo!\common\yiesrvc.dll
DPF: Microsoft XML Parser for Java - file://c:\windows\java\classes\xmldso.cab
DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} - c:\program files\yahoo!\common\Yinsthelper200711281.dll
DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} - hxxp://spaces.msn.com//PhotoUpload/MsnPUpld.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/products/plugin/autodl/jinstall-142-windows-i586.cab
DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} - hxxp://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} - hxxp://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
DPF: {CAFEEFAC-0014-0002-0003-ABCDEFFEDCBA} - hxxp://java.sun.com/products/plugin/autodl/jinstall-142-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg8\avgpp.dll
Notify: avgrsstarter - avgrsstx.dll
Notify: igfxcui - igfxdev.dll
Notify: IntelWireless - c:\program files\intel\wireless\bin\LgNotify.dll
LSA: Notification Packages = scecli

============= SERVICES / DRIVERS ===============

R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2009-6-9 114768]
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2009-6-13 327688]
R1 AvgMfx86;AVG Free On-access Scanner Minifilter Driver x86;c:\windows\system32\drivers\avgmfx86.sys [2009-6-13 27784]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2009-6-13 108552]
R2 aawservice;Lavasoft Ad-Aware Service;c:\program files\lavasoft\ad-aware\aawservice.exe [2008-9-10 611664]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2009-6-9 20560]
R2 avast! Antivirus;avast! Antivirus;c:\program files\alwil software\avast4\ashServ.exe [2009-6-9 138680]
R2 avg8emc;AVG Free8 E-mail Scanner;c:\progra~1\avg\avg8\avgemc.exe [2009-6-13 908568]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\avg\avg8\avgwdsvc.exe [2009-6-13 298776]
R3 avast! Mail Scanner;avast! Mail Scanner;c:\program files\alwil software\avast4\ashMaiSv.exe [2009-6-9 254040]
R3 avast! Web Scanner;avast! Web Scanner;c:\program files\alwil software\avast4\ashWebSv.exe [2009-6-9 352920]
R3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [2009-6-18 38160]

=============== Created Last 30 ================

2009-06-18 16:26 38,160 a------- c:\windows\system32\drivers\mbamswissarmy.sys
2009-06-18 16:26 19,096 a------- c:\windows\system32\drivers\mbam.sys
2009-06-18 16:26 --d----- c:\program files\Malwarebytes' Anti-Malware
2009-06-18 14:19 --d----- c:\docume~1\keithw~1.swi\applic~1\Malwarebytes
2009-06-18 14:19 --d----- c:\docume~1\alluse~1\applic~1\Malwarebytes
2009-06-18 10:04 --d----- c:\program files\Microsoft CAPICOM 2.1.0.2
2009-06-18 09:13 268,648 a------- c:\windows\system32\mucltui.dll
2009-06-18 09:13 208,744 a------- c:\windows\system32\muweb.dll
2009-06-18 09:13 27,496 a------- c:\windows\system32\mucltui.dll.mui
2009-06-16 10:23 --d----- c:\documents and settings\keith wright.swizzle\Tracing
2009-06-16 10:19 --d----- c:\program files\Microsoft
2009-06-16 10:19 --d----- c:\program files\Windows Live SkyDrive
2009-06-16 10:13 --d----- c:\program files\common files\Windows Live
2009-06-13 19:12 --d-h--- C:\$AVG8.VAULT$
2009-06-13 18:54 11,952 a------- c:\windows\system32\avgrsstx.dll
2009-06-13 18:54 108,552 a------- c:\windows\system32\drivers\avgtdix.sys
2009-06-13 18:53 327,688 a------- c:\windows\system32\drivers\avgldx86.sys
2009-06-13 18:53 --d----- c:\windows\system32\drivers\Avg
2009-06-13 18:53 --d----- c:\program files\AVG
2009-06-13 18:53 --d----- c:\docume~1\alluse~1\applic~1\avg8
2009-06-13 18:38 --dsh--- c:\documents and settings\keith wright.swizzle\PrivacIE
2009-06-13 10:45 --d----- c:\program files\Spybot - Search & Destroy
2009-06-13 10:45 --d----- c:\docume~1\alluse~1\applic~1\Spybot - Search & Destroy
2009-06-13 08:49 --d----- c:\windows\network diagnostic
2009-06-13 08:43 1,689,088 a------- c:\windows\system32\d3d9.dll
2009-06-13 08:42 426,041 a------- c:\windows\system32\dllcache\voicepad.dll
2009-06-13 08:41 294,912 a------- c:\windows\system32\msaud32.acm
2009-06-13 08:40 985,088 a------- c:\windows\system32\setupapi.dll
2009-06-13 08:27 --dsh--- c:\documents and settings\keith wright.swizzle\IETldCache
2009-06-13 08:18 12,800 -c------ c:\windows\system32\dllcache\xpshims.dll
2009-06-13 08:18 1,985,024 -c------ c:\windows\system32\dllcache\iertutil.dll
2009-06-13 08:18 11,064,832 -c------ c:\windows\system32\dllcache\ieframe.dll
2009-06-13 08:18 246,272 -c------ c:\windows\system32\dllcache\ieproxy.dll
2009-06-13 08:18 --d----- c:\windows\ie8updates
2009-06-13 08:18 102,912 -c------ c:\windows\system32\dllcache\iecompat.dll
2009-06-13 08:15 -cd-h--- c:\windows\ie8
2009-06-13 02:03 139,536 a------- c:\windows\system32\javaee.dll
2009-06-13 01:44 --d----- c:\program files\Lavasoft
2009-06-13 01:00 23,040 ac------ c:\windows\system32\dllcache\xrxwbtmp.dll
2009-06-13 01:00 27,648 ac------ c:\windows\system32\dllcache\xrxftplt.exe
2009-06-13 01:00 4,608 ac------ c:\windows\system32\dllcache\xrxflnch.exe
2009-06-13 00:59 99,865 ac------ c:\windows\system32\dllcache\xlog.exe
2009-06-13 00:59 16,970 ac------ c:\windows\system32\dllcache\xem336n5.sys
2009-06-13 00:59 19,455 ac------ c:\windows\system32\dllcache\wvchntxx.sys
2009-06-13 00:59 12,063 ac------ c:\windows\system32\dllcache\wsiintxx.sys
2009-06-13 00:59 154,624 ac------ c:\windows\system32\dllcache\wlluc48.sys
2009-06-13 00:57 19,016 ac------ c:\windows\system32\dllcache\w926nd.sys
2009-06-13 00:57 19,528 ac------ c:\windows\system32\dllcache\w840nd.sys
2009-06-13 00:57 64,605 ac------ c:\windows\system32\dllcache\vvoice.sys
2009-06-13 00:57 397,502 ac------ c:\windows\system32\dllcache\vpctcom.sys
2009-06-13 00:57 604,253 ac------ c:\windows\system32\dllcache\vmodem.sys
2009-06-13 00:57 249,402 ac------ c:\windows\system32\dllcache\vinwm.sys
2009-06-13 00:57 24,576 ac------ c:\windows\system32\dllcache\viairda.sys
2009-06-13 00:57 687,999 ac------ c:\windows\system32\dllcache\usrwdxjs.sys
2009-06-13 00:57 765,884 ac------ c:\windows\system32\dllcache\usrti.sys
2009-06-13 00:57 113,762 ac------ c:\windows\system32\dllcache\usrpda.sys
2009-06-13 00:57 7,556 ac------ c:\windows\system32\dllcache\usroslba.sys
2009-06-13 00:57 224,802 ac------ c:\windows\system32\dllcache\usr1807a.sys
2009-06-13 00:56 794,399 ac------ c:\windows\system32\dllcache\usr1806v.sys
2009-06-13 00:56 793,598 ac------ c:\windows\system32\dllcache\usr1806.sys
2009-06-13 00:56 794,654 ac------ c:\windows\system32\dllcache\usr1801.sys
2009-06-13 00:56 32,384 ac------ c:\windows\system32\dllcache\usb101et.sys
2009-06-13 00:56 94,720 ac------ c:\windows\system32\dllcache\umaxud32.dll
2009-06-13 00:56 28,160 ac------ c:\windows\system32\dllcache\umaxu40.dll
2009-06-13 00:56 26,624 ac------ c:\windows\system32\dllcache\umaxu22.dll
2009-06-13 00:56 69,632 ac------ c:\windows\system32\dllcache\umaxu12.dll
2009-06-13 00:56 50,688 ac------ c:\windows\system32\dllcache\umaxscan.dll
2009-06-13 00:56 22,912 ac------ c:\windows\system32\dllcache\umaxpcls.sys
2009-06-13 00:56 50,176 ac------ c:\windows\system32\dllcache\umaxp60.dll
2009-06-13 00:56 47,616 ac------ c:\windows\system32\dllcache\umaxcam.dll
2009-06-13 00:55 211,968 ac------ c:\windows\system32\dllcache\um54scan.dll
2009-06-13 00:55 216,064 ac------ c:\windows\system32\dllcache\um34scan.dll
2009-06-13 00:55 11,520 ac------ c:\windows\system32\dllcache\twotrack.sys
2009-06-13 00:55 166,784 ac------ c:\windows\system32\dllcache\tridxpm.sys
2009-06-13 00:55 525,568 ac------ c:\windows\system32\dllcache\tridxp.dll
2009-06-13 00:55 159,232 ac------ c:\windows\system32\dllcache\tridkbm.sys
2009-06-13 00:55 440,576 ac------ c:\windows\system32\dllcache\tridkb.dll
2009-06-13 00:55 222,336 ac------ c:\windows\system32\dllcache\trid3dm.sys
2009-06-13 00:55 315,520 ac------ c:\windows\system32\dllcache\trid3d.dll
2009-06-13 00:55 34,375 ac------ c:\windows\system32\dllcache\tpro4.sys
2009-06-13 00:55 42,496 ac------ c:\windows\system32\dllcache\tp4res.dll
2009-06-13 00:55 31,744 ac------ c:\windows\system32\dllcache\tp4.dll
2009-06-13 00:54 230,912 ac------ c:\windows\system32\dllcache\tosdvd03.sys
2009-06-13 00:54 241,664 ac------ c:\windows\system32\dllcache\tosdvd02.sys
2009-06-13 00:54 28,232 ac------ c:\windows\system32\dllcache\tos4mo.sys
2009-06-13 00:54 123,995 ac------ c:\windows\system32\dllcache\tjisdn.sys
2009-06-13 00:54 138,528 ac------ c:\windows\system32\dllcache\tgiulnt5.sys
2009-06-13 00:54 81,408 ac------ c:\windows\system32\dllcache\tgiul50.dll
2009-06-13 00:54 17,129 ac------ c:\windows\system32\dllcache\tdkcd31.sys
2009-06-13 00:54 37,961 ac------ c:\windows\system32\dllcache\tdk100b.sys
2009-06-13 00:54 30,464 ac------ c:\windows\system32\dllcache\tbatm155.sys
2009-06-13 00:54 7,040 ac------ c:\windows\system32\dllcache\tandqic.sys
2009-06-13 00:54 36,640 ac------ c:\windows\system32\dllcache\t2r4mini.sys
2009-06-13 00:54 172,768 ac------ c:\windows\system32\dllcache\t2r4disp.dll
2009-06-13 00:52 24,660 ac------ c:\windows\system32\dllcache\spxupchk.dll
2009-06-13 00:52 61,824 ac------ c:\windows\system32\dllcache\speed.sys
2009-06-13 00:52 106,584 ac------ c:\windows\system32\dllcache\spdports.dll
2009-06-13 00:52 37,040 ac------ c:\windows\system32\dllcache\sonypi.sys
2009-06-13 00:52 114,688 ac------ c:\windows\system32\dllcache\sonypi.dll
2009-06-13 00:52 20,752 ac------ c:\windows\system32\dllcache\sonync.sys
2009-06-13 00:52 9,600 ac------ c:\windows\system32\dllcache\sonymc.sys
2009-06-13 00:52 7,040 ac------ c:\windows\system32\dllcache\snyaitmc.sys
2009-06-13 00:52 58,368 ac------ c:\windows\system32\dllcache\smiminib.sys
2009-06-13 00:52 147,200 ac------ c:\windows\system32\dllcache\smidispb.dll
2009-06-13 00:52 25,034 ac------ c:\windows\system32\dllcache\smcpwr2n.sys
2009-06-13 00:52 35,913 ac------ c:\windows\system32\dllcache\smcirda.sys
2009-06-13 00:50 68,608 ac------ c:\windows\system32\dllcache\sis6306p.sys
2009-06-13 00:50 252,032 ac------ c:\windows\system32\dllcache\sis300iv.dll
2009-06-13 00:50 101,760 ac------ c:\windows\system32\dllcache\sis300ip.sys
2009-06-13 00:50 161,568 ac------ c:\windows\system32\dllcache\sgsmusb.sys
2009-06-13 00:50 18,400 ac------ c:\windows\system32\dllcache\sgsmld.sys
2009-06-13 00:50 98,080 ac------ c:\windows\system32\dllcache\sgiulnt5.sys
2009-06-13 00:50 386,560 ac------ c:\windows\system32\dllcache\sgiul50.dll
2009-06-13 00:50 36,480 ac------ c:\windows\system32\dllcache\sfmanm.sys
2009-06-13 00:50 6,784 ac------ c:\windows\system32\dllcache\serscan.sys
2009-06-13 00:50 17,664 ac------ c:\windows\system32\dllcache\sermouse.sys
2009-06-13 00:50 6,912 ac------ c:\windows\system32\dllcache\seaddsmc.sys
2009-06-13 00:50 11,648 ac------ c:\windows\system32\dllcache\scsiprnt.sys
2009-06-13 00:48 182,272 ac------ c:\windows\system32\dllcache\s3mt3d.dll
2009-06-13 00:48 166,720 ac------ c:\windows\system32\dllcache\s3m.sys
2009-06-13 00:48 166,912 ac------ c:\windows\system32\dllcache\s3gnbm.sys
2009-06-13 00:48 65,664 ac------ c:\windows\system32\dllcache\s3legacy.sys
2009-06-13 00:48 82,432 ac------ c:\windows\system32\dllcache\rwia450.dll
2009-06-13 00:48 79,872 ac------ c:\windows\system32\dllcache\rwia430.dll
2009-06-13 00:48 20,992 ac------ c:\windows\system32\dllcache\rtl8139.sys
2009-06-13 00:48 19,017 ac------ c:\windows\system32\dllcache\rtl8029.sys
2009-06-13 00:48 30,720 ac------ c:\windows\system32\dllcache\rthwcls.sys
2009-06-13 00:48 9,216 ac------ c:\windows\system32\dllcache\rsmgrstr.dll
2009-06-13 00:48 3,840 ac------ c:\windows\system32\dllcache\rpfun.sys
2009-06-13 00:48 37,563 ac------ c:\windows\system32\dllcache\rlnet5.sys
2009-06-13 00:48 86,097 ac------ c:\windows\system32\dllcache\reslog32.dll
2009-06-13 00:47 13,776 ac------ c:\windows\system32\dllcache\recagent.sys
2009-06-13 00:47 19,584 ac------ c:\windows\system32\dllcache\rasirda.sys
2009-06-13 00:47 714,762 ac------ c:\windows\system32\dllcache\r2mdmkxx.sys
2009-06-13 00:47 899,146 ac------ c:\windows\system32\dllcache\r2mdkxga.sys
2009-06-13 00:47 41,472 ac------ c:\windows\system32\dllcache\qvusd.dll
2009-06-13 00:47 3,328 ac------ c:\windows\system32\dllcache\qv2kux.sys
2009-06-13 00:47 130,942 ac------ c:\windows\system32\dllcache\ptserlv.sys
2009-06-13 00:47 112,574 ac------ c:\windows\system32\dllcache\ptserlp.sys
2009-06-13 00:47 128,286 ac------ c:\windows\system32\dllcache\ptserli.sys
2009-06-13 00:47 5,632 ac------ c:\windows\system32\dllcache\ptpusb.dll
2009-06-13 00:47 35,328 ac------ c:\windows\system32\dllcache\psisload.dll
2009-06-13 00:45 29,769 ac------ c:\windows\system32\dllcache\pcntn5m.sys
2009-06-13 00:44 43,689 ac------ c:\windows\system32\dllcache\otceth5.sys
2009-06-13 00:44 27,209 ac------ c:\windows\system32\dllcache\otc06x5.sys
2009-06-13 00:44 54,528 ac------ c:\windows\system32\dllcache\opl3sax.sys
2009-06-13 00:44 198,144 ac------ c:\windows\system32\dllcache\nv3.sys
2009-06-13 00:44 123,776 ac------ c:\windows\system32\dllcache\nv3.dll
2009-06-13 00:44 180,360 ac------ c:\windows\system32\dllcache\ntmtlfax.sys
2009-06-13 00:44 51,552 ac------ c:\windows\system32\dllcache\ntgrip.sys
2009-06-13 00:44 9,344 ac------ c:\windows\system32\dllcache\ntapm.sys
2009-06-13 00:44 7,552 ac------ c:\windows\system32\dllcache\nsmmc.sys
2009-06-13 00:44 87,040 ac------ c:\windows\system32\dllcache\nm6wdm.sys
2009-06-13 00:44 126,080 ac------ c:\windows\system32\dllcache\nm5a2wdm.sys
2009-06-13 00:44 32,840 ac------ c:\windows\system32\dllcache\ngrpci.sys
2009-06-13 00:42 19,968 ac------ c:\windows\system32\dllcache\mxicfg.dll
2009-06-13 00:42 21,888 ac------ c:\windows\system32\dllcache\mxcard.sys
2009-06-13 00:42 103,296 ac------ c:\windows\system32\dllcache\mtxvideo.sys
2009-06-13 00:42 452,736 ac------ c:\windows\system32\dllcache\mtxparhm.sys
2009-06-13 00:42 1,309,184 ac------ c:\windows\system32\dllcache\mtlstrm.sys
2009-06-13 00:42 126,686 ac------ c:\windows\system32\dllcache\mtlmnt5.sys
2009-06-13 00:42 12,416 ac------ c:\windows\system32\dllcache\msriffwv.sys
2009-06-13 00:42 2,944 ac------ c:\windows\system32\dllcache\msmpu401.sys
2009-06-13 00:42 35,200 ac------ c:\windows\system32\dllcache\msgame.sys
2009-06-13 00:42 6,016 ac------ c:\windows\system32\dllcache\msfsio.sys
2009-06-13 00:41 16,128 ac------ c:\windows\system32\dllcache\modemcsa.sys
2009-06-13 00:41 6,528 ac------ c:\windows\system32\dllcache\miniqic.sys
2009-06-13 00:41 320,384 ac------ c:\windows\system32\dllcache\mgaum.sys
2009-06-13 00:41 235,648 ac------ c:\windows\system32\dllcache\mgaud.dll
2009-06-13 00:41 47,616 ac------ c:\windows\system32\dllcache\memgrp.dll
2009-06-13 00:41 8,320 ac------ c:\windows\system32\dllcache\memcard.sys
2009-06-13 00:41 164,586 ac------ c:\windows\system32\dllcache\mdgndis5.sys
2009-06-13 00:41 7,424 ac------ c:\windows\system32\dllcache\mammoth.sys
2009-06-13 00:39 8,192 ac------ c:\windows\system32\dllcache\kbdkor.dll
2009-06-13 00:39 8,704 ac------ c:\windows\system32\dllcache\kbdjpn.dll
2009-06-13 00:39 5,632 ac------ c:\windows\system32\dllcache\kbd103.dll
2009-06-13 00:39 6,144 ac------ c:\windows\system32\dllcache\kbd101c.dll
2009-06-13 00:39 6,144 ac------ c:\windows\system32\dllcache\kbd101b.dll
2009-06-13 00:39 26,624 ac------ c:\windows\system32\dllcache\irstusb.sys
2009-06-13 00:39 18,688 ac------ c:\windows\system32\dllcache\irsir.sys
2009-06-13 00:39 23,552 ac------ c:\windows\system32\dllcache\irmk7.sys
2009-06-13 00:38 45,632 ac------ c:\windows\system32\dllcache\ip5515.sys
2009-06-13 00:38 90,200 ac------ c:\windows\system32\dllcache\io8ports.dll
2009-06-13 00:38 38,784 ac------ c:\windows\system32\dllcache\io8.sys
2009-06-13 00:38 13,056 ac------ c:\windows\system32\dllcache\inport.sys
2009-06-13 00:38 372,824 ac------ c:\windows\system32\dllcache\iconf32.dll
2009-06-13 00:38 100,992 ac------ c:\windows\system32\dllcache\icam5usb.sys
2009-06-13 00:38 20,480 ac------ c:\windows\system32\dllcache\icam5ext.dll
2009-06-13 00:38 45,056 ac------ c:\windows\system32\dllcache\icam5com.dll
2009-06-13 00:38 154,496 ac------ c:\windows\system32\dllcache\icam4usb.sys
2009-06-13 00:38 61,952 ac------ c:\windows\system32\dllcache\icam4ext.dll
2009-06-13 00:37 91,136 ac------ c:\windows\system32\dllcache\icam4com.dll
2009-06-13 00:37 26,624 ac------ c:\windows\system32\dllcache\icam3ext.dll
2009-06-13 00:37 141,056 ac------ c:\windows\system32\dllcache\icam3.sys
2009-06-13 00:37 38,528 ac------ c:\windows\system32\dllcache\ibmvcap.sys
2009-06-13 00:37 109,085 ac------ c:\windows\system32\dllcache\ibmtrp.sys
2009-06-13 00:37 100,936 ac------ c:\windows\system32\dllcache\ibmtok.sys
2009-06-13 00:37 9,216 ac------ c:\windows\system32\dllcache\ibmsgnet.dll
2009-06-13 00:37 28,700 ac------ c:\windows\system32\dllcache\ibmexmp.sys
2009-06-13 00:37 161,020 ac------ c:\windows\system32\dllcache\i81xnt5.sys
2009-06-13 00:37 58,592 ac------ c:\windows\system32\dllcache\i740nt5.sys
2009-06-13 00:37 353,184 ac------ c:\windows\system32\dllcache\i740dnt5.dll
2009-06-13 00:35 68,608 ac------ c:\windows\system32\dllcache\hpgt53tk.dll
2009-06-13 00:34 322,432 ac------ c:\windows\system32\dllcache\g400m.sys
2009-06-13 00:33 12,362 ac------ c:\windows\system32\dllcache\f3ab18xi.sys
2009-06-13 00:32 18,503 ac------ c:\windows\system32\dllcache\epro4.sys
2009-06-13 00:31 29,696 ac------ c:\windows\system32\dllcache\dm9pci5.sys
2009-06-13 00:30 117,760 ac------ c:\windows\system32\dllcache\d100ib5.sys
2009-06-13 00:29 49,182 ac------ c:\windows\system32\dllcache\cem56n5.sys
2009-06-13 00:28 41,472 ac------ c:\windows\system32\dllcache\brmfusb.dll
2009-06-13 00:27 97,354 ac------ c:\windows\system32\dllcache\aspndis3.sys
2009-06-13 00:26 66,048 ac------ c:\windows\system32\dllcache\s3legacy.dll
2009-06-12 23:39 --d----- c:\program files\common files\Wise Installation Wizard
2009-06-12 23:36 --d----- c:\program files\CCleaner
2009-06-12 23:28 664 a------- c:\windows\system32\d3d9caps.dat
2009-06-12 23:27 54,156 a---h--- c:\windows\QTFont.qfn
2009-06-12 23:27 1,409 a------- c:\windows\QTFont.for
2009-06-12 16:31 --d----- c:\windows\pss
2009-05-28 14:39 74,240 a------- c:\windows\system32\zlib.dll

==================== Find3M ====================

2009-06-13 09:10 88,713 a------- c:\windows\pchealth\helpctr\offlinecache\index.dat
2009-06-13 02:03 2,678 a------- c:\windows\java\packages\data\c9fpzdjl.dat
2009-06-13 02:03 2,678 a------- c:\windows\java\packages\data\6yue4jbv.dat
2009-06-13 02:03 2,678 a------- c:\windows\java\packages\data\l73lftv9.dat
2009-06-13 02:03 2,678 a------- c:\windows\java\packages\data\zhf1nt3l.dat
2009-06-13 02:03 2,678 a------- c:\windows\java\packages\data\gexfpv1n.dat
2009-05-13 06:15 915,456 a------- c:\windows\system32\wininet.dll
2009-04-29 05:52 81,920 a------- c:\windows\system32\ieencode.dll
2009-04-15 16:11 584,192 -------- c:\windows\system32\rpcrt4.dll
2009-03-21 15:18 986,112 a------- c:\windows\system32\kbdpx.dll

============= FINISH: 18:14:27.93 ===============

Edited by Orange Blossom, 18 June 2009 - 07:50 PM.


BC AdBot (Login to Remove)

 


#2 thcbytes

thcbytes

  • Malware Response Team
  • 14,790 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:10:15 AM

Posted 24 June 2009 - 08:38 AM

Hello and welcome to Bleeping Computer

We apologize for the delay in responding to your request for help. Here at Bleeping Computer we get overwhelmed at times, and we are trying our best to keep up. Please note that your topic was not intentionally overlooked. Our mission is to help everyone in need, but sometimes it takes just a little longer to get to every request for help. No one is ignored here.

If you have since resolved the original problem you were having, we would appreciate you letting us know. If not please perform the following steps below so we can have a look at the current condition of your machine.

If you have not done so, include a clear description of the problems you're having, along with any steps you may have performed so far.

Upon completing the steps below another staff member will review and take the steps necessary with you to get your machine back in working order clean and free of malware.

If you have already posted a DDS log, please do so again, as your situation may have changed.
Use the 'Add Reply' and add the new log to this thread.


Thanks and again sorry for the delay.

We need to see some information about what is happening in your machine. Please perform the following scan:
  • Download DDS by sUBs from one of the following links. Save it to your desktop.
  • Double click on the DDS icon, allow it to run.
  • A small box will open, with an explaination about the tool. No input is needed, the scan is running.
  • Notepad will open with the results.
  • Follow the instructions that pop up for posting the results.
  • Close the program window, and delete the program from your desktop.
Please note: You may have to disable any script protection running if the scan fails to run. After downloading the tool, disconnect from the internet and disable all antivirus protection. Run the scan, enable your A/V and reconnect to the internet.

Information on A/V control HERE
Proud member - Unified Network of Instructors and Trained Eliminators
Posted Image

I do not accept personal donations for assistance provided. I would ask that you instead consider donating the greatest gift - Organ Donation. Your organs are of no use to you when your gone. You will save a life that would otherwise be lost!

http://donatelife.net/register-now/

#3 Wadey

Wadey
  • Topic Starter

  • Members
  • 10 posts
  • OFFLINE
  •  
  • Local time:04:15 PM

Posted 25 June 2009 - 01:13 PM

Hi there, thanks for getting back to me.

I have managed to retrieve any data I had on the machine, delete the partitions and started over.

Thanks anyway!

Ash

#4 Orange Blossom

Orange Blossom

    OBleepin Investigator


  • Moderator
  • 37,112 posts
  • OFFLINE
  •  
  • Gender:Not Telling
  • Location:Bloomington, IN
  • Local time:10:15 AM

Posted 25 June 2009 - 08:23 PM

Hello

Thank you for posting back. I'm glad that your computer problems have been fixed. Since this issue seems to be resolved, this thread will now be closed.

In case you experience any problems with the computer, please start a new topic.

Happy computing,

Orange Blossom :thumbup2:
Help us help you. If HelpBot replies, you MUST follow step 1 in its reply so we know you need help.

Orange Blossom

An ounce of prevention is worth a pound of cure

SpywareBlaster, WinPatrol Plus, ESET Internet Security, NoScript Firefox ext.


animinionsmalltext.gif




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users