Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

netframe error.. not sure what virus my pc have.. pls help


  • This topic is locked This topic is locked
3 replies to this topic

#1 sunogbaga12

sunogbaga12

  • Members
  • 3 posts
  • OFFLINE
  •  
  • Local time:05:20 PM

Posted 30 January 2010 - 12:30 AM



i am not really familiar with computer problem.
my compter hangs very often and some netframe error accuring every startup.

pls pls pls help..


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:24:54 AM, on 1/1/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\AskBarDis\bar\bin\AskService.exe
C:\Program Files\AskBarDis\bar\bin\ASKUpgrade.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Norton AntiVirus\Engine\16.5.0.134\ccSvcHst.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\tbh\monitor\bin\tbhMonitor.exe
C:\Program Files\Xobni\XobniService.exe
c:\Program Files\tbh\base\bin\tbhDaemon.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\VMSnap3.EXE
C:\WINDOWS\Domino.EXE
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\vsnpstd.exe
C:\WINDOWS\vsnpstd2.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\tbh\base\bin\tbhSystray.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Norton AntiVirus\Engine\16.5.0.134\ccSvcHst.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\wuauclt.exe
C:\DOCUME~1\jasd\LOCALS~1\Temp\Temporary Directory 1 for HijackThis(2).zip\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://toolbar.ask.com/toolbarv/askRedirec...amp;gc=1&q=
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul...rch/search.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://home.sweetim.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Search_URL = http://toolbar.ask.com/toolbarv/askRedirec...amp;gc=1&q=
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://toolbar.ask.com/toolbarv/askRedirec...p;gc=1&q=%s
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.bullguard.com/buy.aspx
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
R3 - URLSearchHook: DefaultSearchHook Class - {C94E154B-1459-4A47-966B-4B843BEFC7DB} - (no file)
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: AskBar BHO - {201f27d4-3704-41d6-89c1-aa35e39143ed} - C:\Program Files\AskBarDis\bar\bin\askBar.dll
O2 - BHO: Your Browser Search - {3E6BBE25-EAA3-457d-94F0-0D023EFFA3EF} - C:\Program Files\yourbrowsersearchTb\dtx.dll
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton AntiVirus\Engine\16.5.0.134\IPSBHO.DLL
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\YTSingleInstance.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O3 - Toolbar: Ask Toolbar - {3041d03e-fd4b-44e0-b742-2d9b88305f98} - C:\Program Files\AskBarDis\bar\bin\askBar.dll
O3 - Toolbar: Your Browser Search - {3E6BBE25-EAA3-457d-94F0-0D023EFFA3EF} - C:\Program Files\yourbrowsersearchTb\dtx.dll
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [VMSnap3] C:\WINDOWS\VMSnap3.EXE
O4 - HKLM\..\Run: [Domino] C:\WINDOWS\Domino.EXE
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [snpstd] C:\WINDOWS\vsnpstd.exe
O4 - HKLM\..\Run: [SNPSTD2] C:\WINDOWS\vsnpstd2.exe
O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [tbhSystray] C:\Program Files\tbh\base\bin\tbhSystray.exe
O4 - HKLM\..\Run: [BigDog303] C:\WINDOWS\VM303_STI.EXE VIMICRO USB PC Camera (ZC0301PLH)
O4 - HKCU\..\Run: [Messenger (Yahoo!)] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [] C:\WINDOWS\system32\scvhost.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {48884C41-EFAC-433D-958A-9FADAC41408E} (EGamesPlugin Class) - https://www.e-games.com.ph/com/EGamesPlugin.cab
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: ASKService - Unknown owner - C:\Program Files\AskBarDis\bar\bin\AskService.exe
O23 - Service: ASKUpgrade - Unknown owner - C:\Program Files\AskBarDis\bar\bin\ASKUpgrade.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Norton AntiVirus - Symantec Corporation - C:\Program Files\Norton AntiVirus\Engine\16.5.0.134\ccSvcHst.exe
O23 - Service: nProtect GameGuard Service (npggsvc) - Unknown owner - C:\WINDOWS\system32\GameMon.des.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: The Browser Highlighter Monitor (tbhMonitor.exe) - Unknown owner - C:\Program Files\tbh\monitor\bin\tbhMonitor.exe
O23 - Service: XobniService - Xobni Corporation - C:\Program Files\Xobni\XobniService.exe
O23 - Service: Yahoo! Updater (YahooAUService) - Yahoo! Inc. - C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe

--
End of file - 7671 bytes


BC AdBot (Login to Remove)

 


#2 sunogbaga12

sunogbaga12
  • Topic Starter

  • Members
  • 3 posts
  • OFFLINE
  •  
  • Local time:05:20 PM

Posted 30 January 2010 - 02:42 PM

i scanned my pc with BULLGUARD,a Trojan was found and kept it quaranteen.but still my pc have problem like:computer shutdown, slow pc performance,Microsoft .NET framework error msg during start up (unhandled exception has occurred in your application. if you click continue, the application will ignore this error and attempt to continue. if you click quit, theapplication will close immediately. index was outside the bounds of the array).


DDS (Ver_09-12-01.01) - NTFSx86
Run by jasd at 8:36:11.21 on Mon 01/01/2007
Internet Explorer: 6.0.2900.2180 BrowserJavaVersion: 1.6.0_17
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.510.137 [GMT 8:00]

AV: Norton AntiVirus *On-access scanning enabled* (Updated) {E10A9785-9598-4754-B552-92431C1C35F8}

============== Running Processes ===============

C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\AskBarDis\bar\bin\AskService.exe
C:\Program Files\AskBarDis\bar\bin\ASKUpgrade.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Norton AntiVirus\Engine\16.5.0.134\ccSvcHst.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files\tbh\monitor\bin\tbhMonitor.exe
C:\Program Files\Xobni\XobniService.exe
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\VMSnap3.EXE
C:\WINDOWS\Domino.EXE
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\vsnpstd.exe
C:\WINDOWS\vsnpstd2.exe
c:\Program Files\tbh\base\bin\tbhDaemon.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\tbh\base\bin\tbhSystray.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\scvhost.exe
C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Norton AntiVirus\Engine\16.5.0.134\ccSvcHst.exe
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\jasd\Desktop\dds.scr

============== Pseudo HJT Report ===============

uStart Page = hxxp://yahoo.com/
uSearch Page =
uSearch Bar =
mDefault_Search_URL = hxxp://toolbar.ask.com/toolbarv/askRedirect?o=10615&gct=&gc=1&q=
mStart Page = hxxp://home.sweetim.com
mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr9/*http://www.yahoo.com/ext/search/search.html
uInternet Connection Wizard,ShellNext = hxxp://www.bullguard.com/buy.aspx
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://toolbar.ask.com/toolbarv/askRedirect?o=10615&gct=&gc=1&q=%s
mSearchAssistant =
uURLSearchHooks: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn0\yt.dll
uURLSearchHooks: DefaultSearchHook Class: {c94e154b-1459-4a47-966b-4b843befc7db} -
BHO: &Yahoo! Toolbar Helper: {02478d38-c3f9-4efb-9b51-7695eca05670} - c:\program files\yahoo!\companion\installs\cpn0\yt.dll
BHO: AskBar BHO: {201f27d4-3704-41d6-89c1-aa35e39143ed} - c:\program files\askbardis\bar\bin\askBar.dll
BHO: Your Browser Search: {3e6bbe25-eaa3-457d-94f0-0d023effa3ef} - c:\program files\yourbrowsersearchtb\dtx.dll
BHO: Symantec Intrusion Prevention: {6d53ec84-6aae-4787-aeee-f4628f01010c} - c:\program files\norton antivirus\engine\16.5.0.134\IPSBHO.DLL
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
BHO: SingleInstance Class: {fdad4da1-61a2-4fd8-9c17-86f7ac245081} - c:\program files\yahoo!\companion\installs\cpn0\YTSingleInstance.dll
TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn0\yt.dll
TB: Ask Toolbar: {3041d03e-fd4b-44e0-b742-2d9b88305f98} - c:\program files\askbardis\bar\bin\askBar.dll
TB: Your Browser Search: {3e6bbe25-eaa3-457d-94f0-0d023effa3ef} - c:\program files\yourbrowsersearchtb\dtx.dll
TB: {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No File
TB: {EEE6C35B-6118-11DC-9C72-001320C79847} - No File
uRun: [Messenger (Yahoo!)] "c:\program files\yahoo!\messenger\YahooMessenger.exe" -quiet
uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background
uRun: [<NO NAME>] c:\windows\system32\scvhost.exe
mRun: [RTHDCPL] RTHDCPL.EXE
mRun: [SkyTel] SkyTel.EXE
mRun: [Alcmtr] ALCMTR.EXE
mRun: [VMSnap3] c:\windows\VMSnap3.EXE
mRun: [Domino] c:\windows\Domino.EXE
mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [snpstd] c:\windows\vsnpstd.exe
mRun: [SNPSTD2] c:\windows\vsnpstd2.exe
mRun: [nwiz] nwiz.exe /installquiet
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit
mRun: [tbhSystray] c:\program files\tbh\base\bin\tbhSystray.exe
mRun: [BigDog303] c:\windows\VM303_STI.EXE VIMICRO USB PC Camera (ZC0301PLH)
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://go.microsoft.com/fwlink/?linkid=39204
DPF: {48884C41-EFAC-433D-958A-9FADAC41408E} - hxxps://www.e-games.com.ph/com/EGamesPlugin.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab

================= FIREFOX ===================

FF - ProfilePath - c:\docume~1\jasd\applic~1\mozilla\firefox\profiles\1cc6s21d.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.sweetim.com/search.asp?src=2&q=
FF - prefs.js: browser.search.selectedEngine - SweetIM Search
FF - prefs.js: browser.startup.homepage - hxxp://home.sweetim.com
FF - prefs.js: keyword.URL - hxxp://search.sweetim.com/search.asp?src=2&q=
FF - component: c:\documents and settings\jasd\application data\mozilla\firefox\profiles\1cc6s21d.default\extensions\browserhighlighter@ebay.com\components\Shim.dll
FF - plugin: c:\program files\microsoft\office live\npOLW.dll
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}

---- FIREFOX POLICIES ----
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);

============= SERVICES / DRIVERS ===============

R0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\nav\1005000.086\SymEFA.sys [2007-1-1 310320]
R1 BHDrvx86;Symantec Heuristics Driver;c:\windows\system32\drivers\nav\1005000.086\BHDrvx86.sys [2007-1-1 258608]
R1 BIOS;BIOS;c:\windows\system32\drivers\BIOS.sys [2009-11-13 13696]
R1 ccHP;Symantec Hash Provider;c:\windows\system32\drivers\nav\1005000.086\cchpx86.sys [2007-1-1 482352]
R1 IDSxpx86;IDSxpx86;c:\documents and settings\all users\application data\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\norton\definitions\ipsdefs\20100128.002\IDSXpx86.sys [2007-1-1 329592]
R2 ASKService;ASKService;c:\program files\askbardis\bar\bin\AskService.exe [2007-1-1 464264]
R2 ASKUpgrade;ASKUpgrade;c:\program files\askbardis\bar\bin\ASKUpgrade.exe [2007-1-1 234888]
R2 Norton AntiVirus;Norton AntiVirus;c:\program files\norton antivirus\engine\16.5.0.134\ccSvcHst.exe [2007-1-1 115560]
R2 tbhMonitor.exe;The Browser Highlighter Monitor;c:\program files\tbh\monitor\bin\tbhMonitor.exe [2009-10-22 70952]
R2 XobniService;XobniService;c:\program files\xobni\XobniService.exe [2009-10-13 46824]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\common files\symantec shared\eengine\EraserUtilRebootDrv.sys [2010-1-29 102448]
R3 NAVENG;NAVENG;c:\documents and settings\all users\application data\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\norton\definitions\virusdefs\20100129.064\NAVENG.SYS [2007-1-1 84912]
R3 NAVEX15;NAVEX15;c:\documents and settings\all users\application data\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\norton\definitions\virusdefs\20100129.064\NAVEX15.SYS [2007-1-1 1323568]
R3 nvoclock;NVIDIA Enthusiasts Platform KDM;c:\windows\system32\drivers\nvoclock.sys [2009-9-15 38248]
R3 vmfilter303;vmfilter303;c:\windows\system32\drivers\vmfilter303.sys [2007-1-1 428160]
S3 npggsvc;nProtect GameGuard Service;c:\windows\system32\gamemon.des -service --> c:\windows\system32\GameMon.des -service [?]
UnknownUnknown dump_wmimmc;dump_wmimmc; [x]

=============== Created Last 30 ================

2010-01-29 13:14:34 0 d-----w- c:\windows\system32\PreInstall
2010-01-29 13:14:33 0 d--h--w- c:\windows\$hf_mig$
2010-01-29 04:08:04 120832 ----a-w- c:\windows\system32\scvhost.exe
2010-01-06 11:47:28 62 --sha-r- c:\windows\system32\config.bat
2009-11-20 12:32:14 278120 ----a-w- c:\windows\system32\nvmccs.dll
2009-11-20 12:32:14 154216 ----a-w- c:\windows\system32\nvsvc32.exe
2009-11-20 12:32:14 145000 ----a-w- c:\windows\system32\nvcolor.exe
2009-11-20 12:32:14 12669544 ----a-w- c:\windows\system32\nvcpl.dll
2009-11-20 12:32:14 110184 ----a-w- c:\windows\system32\nvmctray.dll
2009-11-20 12:32:10 81920 ----a-w- c:\windows\system32\nvwddi.dll
2009-11-20 12:32:00 9809 ----a-w- c:\windows\system32\NvApps.xml
2009-11-20 12:32:00 64882 ----a-w- c:\windows\system32\NvwsApps.xml
2009-11-16 17:31:18 0 d-----w- c:\documents and settings\jasd\Tracing
2009-11-16 17:07:28 0 d-----w- c:\program files\Windows Live SkyDrive
2009-11-16 16:58:46 0 d-----w- c:\program files\common files\Windows Live
2009-11-13 13:05:54 3597136 ----a-w- c:\windows\system32\GameMon.des
2009-11-13 13:04:23 0 d-----w- c:\program files\common files\INCA Shared
2009-11-13 13:02:09 4682 ----a-w- c:\windows\system32\npptNT2.sys
2009-11-13 13:02:08 5174 ----a-w- c:\windows\system32\nppt9x.vxd
2009-11-13 12:25:36 0 d-----w- c:\program files\e-Games
2009-11-13 11:00:02 421888 ----a-w- c:\windows\system32\ac3filter.acm
2009-11-13 10:58:38 0 d-----w- c:\program files\XP Codec Pack
2009-11-13 09:39:47 26496 -c--a-w- c:\windows\system32\dllcache\usbstor.sys
2009-11-13 08:40:57 0 d-----w- c:\windows\SHELLNEW
2009-11-13 07:05:20 0 d-----w- c:\program files\Yahoo!
2009-11-13 06:59:27 940794 ----a-w- c:\windows\system32\LoopyMusic.wav
2009-11-13 06:59:27 146650 ----a-w- c:\windows\system32\BuzzingBee.wav
2009-11-13 06:59:26 0 d-----w- c:\windows\system32\Lang
2009-11-13 06:58:07 49152 ----a-w- c:\windows\system32\ChCfg.exe
2009-11-13 06:58:06 6400 -c--a-w- c:\windows\system32\dllcache\splitter.sys
2009-11-13 06:58:06 6400 ----a-w- c:\windows\system32\drivers\splitter.sys
2009-11-13 06:58:05 82944 -c--a-w- c:\windows\system32\dllcache\wdmaud.sys
2009-11-13 06:58:05 82944 ----a-w- c:\windows\system32\drivers\wdmaud.sys
2009-11-13 06:58:03 52864 -c--a-w- c:\windows\system32\dllcache\dmusic.sys
2009-11-13 06:58:03 52864 ----a-w- c:\windows\system32\drivers\DMusic.sys
2009-11-13 06:58:00 54272 -c--a-w- c:\windows\system32\dllcache\swmidi.sys
2009-11-13 06:58:00 54272 ----a-w- c:\windows\system32\drivers\swmidi.sys
2009-11-13 06:57:11 0 d-----w- c:\program files\Realtek
2009-11-13 06:56:24 0 d-----w- c:\program files\Driver
2009-11-13 06:56:21 306688 ----a-w- c:\windows\IsUninst.exe
2009-11-13 06:54:11 446464 ----a-w- c:\windows\system32\CapabilityTable.exe
2009-11-13 06:54:05 363008 ----a-r- c:\windows\system32\idecoiins.dll
2009-11-13 06:54:05 363008 ----a-r- c:\windows\system32\idecoi.dll
2009-11-13 06:54:05 35840 ----a-r- c:\windows\system32\NVCOI.DLL
2009-11-13 06:54:05 356352 ------w- c:\windows\system32\nvuide.exe
2009-11-13 06:54:05 1570 ------w- c:\windows\system32\nvide.nvu
2009-11-13 06:54:05 105472 ----a-r- c:\windows\system32\drivers\nvata.sys
2009-11-13 06:54:04 0 d-----w- c:\windows\system32\ReinstallBackups
2009-11-13 06:52:02 13696 ----a-r- c:\windows\system32\drivers\BIOS.sys
2009-11-13 06:26:26 25699 ----a-w- c:\windows\system32\nvdisp.nvu
2009-11-13 06:26:26 0 d-----w- c:\windows\nview
2009-11-13 06:26:25 592488 ----a-w- c:\windows\system32\nvudisp.exe
2009-11-13 06:25:32 592488 ----a-w- c:\windows\system32\NVUNINST.EXE
2009-11-13 06:20:10 0 d-s---w- c:\windows\system32\Microsoft
2009-11-13 06:19:33 8192 ----a-w- c:\windows\REGLOCS.OLD
2009-11-13 05:34:10 0 d-sh--w- c:\documents and settings\all users\DRM
2009-11-13 05:33:50 0 d--h--w- c:\program files\WindowsUpdate
2009-11-13 05:33:00 0 d-----w- c:\program files\common files\MSSoap
2009-11-13 05:31:47 0 d-----w- c:\program files\Online Services
2009-11-13 05:31:42 0 d-----w- c:\program files\Messenger
2009-11-13 05:31:39 0 d-----w- c:\program files\MSN Gaming Zone
2009-11-13 05:31:10 0 d-----w- c:\program files\Windows NT
2007-01-01 02:11:36 0 d-----w- c:\docume~1\alluse~1\applic~1\Symantec
2007-01-01 02:11:36 0 d-----w- c:\docume~1\alluse~1\applic~1\Norton
2007-01-01 02:11:15 0 d-----w- c:\docume~1\alluse~1\applic~1\NortonInstaller
2007-01-01 00:42:22 0 d-----w- c:\program files\common files\ODBC
2007-01-01 00:42:19 0 d-----w- c:\program files\common files\SpeechEngines
2007-01-01 00:41:57 0 d-----r- c:\documents and settings\all users\Documents
2006-12-31 23:25:57 0 d-----w- c:\docume~1\alluse~1\applic~1\NVIDIA Corporation
2006-12-31 23:14:58 0 d-----w- c:\program files\NVIDIA Corporation
2006-12-31 22:02:07 0 d-----w- c:\program files\Eusing Free Registry Cleaner
2006-12-31 21:49:38 0 d-----w- c:\docume~1\alluse~1\applic~1\U3
2006-12-31 21:37:36 0 d-----w- c:\program files\SystemRequirementsLab
2006-12-31 21:24:14 0 d-----w- c:\program files\iXi Tools
2006-12-31 20:26:57 0 d-----w- c:\program files\MP3Resizer
2006-12-31 19:58:10 0 d-----w- c:\program files\Xobni
2006-12-31 19:56:34 0 d-----w- c:\docume~1\jasd\applic~1\dtband
2006-12-31 19:56:03 0 d-----w- c:\docume~1\jasd\applic~1\yourbrowsersearchTb
2006-12-31 19:55:56 0 d-----w- c:\docume~1\jasd\applic~1\yourbrowsersearch
2006-12-31 19:55:53 0 d-----w- c:\program files\yourbrowsersearchTb
2006-12-31 19:38:14 0 d-----w- c:\program files\AskBarDis
2006-12-31 19:12:08 0 d-----w- c:\program files\NCH Software
2006-12-31 18:34:40 0 d-----w- c:\docume~1\jasd\applic~1\LimeWire
2006-12-31 18:23:54 0 d-----w- c:\docume~1\alluse~1\applic~1\Azureus
2006-12-31 18:23:31 0 d-----w- c:\docume~1\jasd\applic~1\Azureus
2006-12-31 18:08:20 0 d-----w- c:\docume~1\jasd\applic~1\MozillaControl
2006-12-31 18:06:25 0 d-----w- c:\program files\Mozilla ActiveX Control v1.7.12
2006-12-31 17:31:39 0 d-----w- c:\program files\common files\snpstd
2006-12-31 17:30:08 0 d-----w- c:\program files\Vimicro
2006-12-31 17:26:15 0 d-----w- c:\program files\tbh
2006-12-31 17:24:14 0 d-----w- c:\docume~1\jasd\applic~1\SmartDraw
2006-12-31 17:19:49 0 d-----w- c:\program files\PhotoScape
2006-12-31 16:54:25 0 d-----w- c:\program files\common files\snpstd2
2006-12-31 16:46:05 0 d-----w- c:\docume~1\alluse~1\applic~1\PopCap Games
2006-12-31 16:45:53 0 d-----w- c:\program files\PopCap Games
2006-12-31 16:43:49 0 d-----w- c:\program files\Symantec
2006-12-31 16:43:49 0 d-----w- c:\program files\common files\Symantec Shared
2006-12-31 16:43:11 0 d-----w- c:\program files\Norton AntiVirus
2006-12-31 16:42:45 0 d-----w- c:\program files\NortonInstaller
2006-12-31 16:40:45 0 d-----w- c:\program files\Microsoft
2006-12-31 16:37:41 0 d-----w- c:\program files\iPod
2006-12-31 16:37:38 0 d-----w- c:\program files\iTunes
2006-12-31 16:37:38 0 d-----w- c:\docume~1\alluse~1\applic~1\{755AC846-7372-4AC8-8550-C52491DAA8BD}
2006-12-31 16:36:18 0 d-----w- c:\program files\Bonjour
2006-12-31 16:32:11 0 d-----w- c:\program files\Canon
2006-12-31 16:30:15 0 d-----w- c:\program files\DivX
2006-12-31 16:21:27 0 d-----w- c:\program files\TrendMicro

==================== Find3M ====================

2009-11-21 02:34:54 69632 ----a-w- c:\windows\system32\OpenCL.dll
2009-11-21 02:34:54 6282752 ----a-w- c:\windows\system32\nv4_disp.dll
2009-11-21 02:34:54 4038656 ----a-w- c:\windows\system32\nvcuda.dll
2009-11-21 02:34:54 2293286 ----a-w- c:\windows\system32\nvdata.bin
2009-11-21 02:34:54 2259560 ----a-w- c:\windows\system32\nvcuvid.dll
2009-11-21 02:34:54 1989224 ----a-w- c:\windows\system32\nvcuvenc.dll
2009-11-21 02:34:54 182888 ----a-w- c:\windows\system32\nvcodins.dll
2009-11-21 02:34:54 182888 ----a-w- c:\windows\system32\nvcod.dll
2009-11-21 02:34:54 13602816 ----a-w- c:\windows\system32\nvoglnt.dll
2009-11-21 02:34:54 11374592 ----a-w- c:\windows\system32\nvcompiler.dll
2009-11-21 02:34:54 1056768 ----a-w- c:\windows\system32\nvapi.dll
2009-11-21 02:34:54 10235968 ----a-w- c:\windows\system32\drivers\nv4_mini.sys
2009-11-13 06:57:08 315392 ----a-w- c:\windows\HideWin.exe
2009-11-13 05:32:08 21640 ----a-w- c:\windows\system32\emptyregdb.dat
2009-09-15 05:59:28 38248 ----a-w- c:\windows\system32\drivers\nvoclock.sys
2009-09-15 05:59:28 162408 ----a-w- c:\windows\system32\nvcoclk.dll
2009-08-06 11:23:46 274288 ----a-w- c:\windows\system32\mucltui.dll
2009-08-06 11:23:46 215920 ----a-w- c:\windows\system32\muweb.dll
2009-06-24 13:39:26 1003520 ----a-w- c:\windows\system32\VSFilter.dll
2008-12-19 14:15:58 4338246 ----a-w- c:\windows\system32\libavcodec.dll
2008-12-17 16:41:18 884237 ----a-w- c:\windows\system32\ff_x264.dll
2008-12-17 16:22:58 93184 ----a-w- c:\windows\system32\ff_wmv9.dll
2008-12-17 16:22:48 57344 ----a-w- c:\windows\system32\ff_vfw.dll
2008-12-17 16:17:34 239247 ----a-w- c:\windows\system32\ff_theora.dll
2008-12-17 15:59:54 560802 ----a-w- c:\windows\system32\libmplayer.dll
2008-12-12 03:18:16 87336 ----a-w- c:\windows\system32\dns-sd.exe
2008-12-12 03:11:46 61440 ----a-w- c:\windows\system32\dnssd.dll
2008-07-11 08:55:41 712704 ------w- c:\windows\system32\windowscodecs.dll
2008-07-11 08:55:41 347648 ------w- c:\windows\system32\windowscodecsext.dll
2008-05-18 22:33:20 4445184 ----a-w- c:\windows\system32\msi.dll
2008-05-18 22:33:20 332800 ----a-w- c:\windows\system32\msihnd.dll
2008-05-18 22:33:20 18944 ----a-w- c:\windows\system32\msisip.dll
2008-05-18 17:57:42 95744 ----a-w- c:\windows\system32\msiexec.exe
2008-04-16 17:43:24 2560 ----a-w- c:\windows\system32\msimsg.dll
2007-10-16 10:38:30 4615168 ----a-w- c:\windows\system32\drivers\RtkHDAud.sys
2007-10-16 10:30:10 16855552 ----a-w- c:\windows\RTHDCPL.exe
2007-10-11 03:04:04 1826816 ----a-w- c:\windows\SkyTel.exe
2007-07-26 10:06:22 1191936 ----a-w- c:\windows\RtlUpd.exe
2007-07-26 09:09:20 520192 ----a-w- c:\windows\RtlExUpd.dll
2007-06-28 08:44:14 2165760 ----a-w- c:\windows\MicCal.exe
2007-03-23 11:19:10 9715200 ----a-w- c:\windows\RTLCPL.exe
2006-12-31 18:20:29 411368 ----a-w- c:\windows\system32\deploytk.dll
2006-12-31 16:43:49 805 ----a-w- c:\windows\system32\drivers\SYMEVENT.INF
2006-12-31 16:43:49 7386 ----a-w- c:\windows\system32\drivers\SYMEVENT.CAT
2006-12-31 16:43:49 60808 ----a-w- c:\windows\system32\S32EVNT1.DLL
2006-12-31 16:43:49 124464 ----a-w- c:\windows\system32\drivers\SYMEVENT.SYS
2006-12-31 16:43:39 36400 ----a-r- c:\windows\system32\drivers\SymIM.sys
2006-12-01 06:23:58 392122 ----a-w- c:\windows\system32\drivers\usbVM303.sys
2006-11-29 05:06:18 3426072 ----a-w- c:\windows\system32\d3dx9_32.dll
2006-11-27 08:33:54 19968 ----a-r- c:\windows\system32\drivers\nvnetbus.sys
2006-11-27 08:33:50 58368 ----a-r- c:\windows\system32\drivers\NVENETFD.sys
2006-11-27 08:33:40 110592 ----a-r- c:\windows\system32\drivers\nvtcp.sys
2006-11-27 08:33:28 895744 ----a-r- c:\windows\system32\drivers\nvnrm.sys
2006-11-27 08:33:06 261632 ----a-r- c:\windows\system32\drivers\nvsnpu.sys
2006-11-27 08:31:50 192512 ----a-r- c:\windows\system32\fdco1ins.dll
2006-11-27 08:31:50 192512 ----a-r- c:\windows\system32\fdco1.dll
2006-11-27 08:31:22 9216 ----a-r- c:\windows\system32\bdco1ins.dll
2006-11-27 08:31:22 9216 ----a-r- c:\windows\system32\bdco1.dll
2006-11-07 06:58:46 35840 ----a-r- c:\windows\system32\nvconrm.dll
2006-11-07 06:58:16 356352 ----a-w- c:\windows\system32\nvunrm.exe
2006-11-02 15:10:16 80912 ----a-w- c:\windows\system32\sherlock2.exe
2006-10-26 06:10:08 1190688 ----a-w- c:\windows\system32\FM20.DLL
2006-10-26 06:10:06 33088 ----a-w- c:\windows\system32\FM20ENU.DLL
2006-10-26 05:45:04 293376 ----a-w- c:\windows\system32\WISPTIS.EXE
2006-10-26 05:45:04 207360 ----a-w- c:\windows\system32\INKED.DLL
2006-10-24 04:30:20 412160 ------w- c:\windows\system32\photometadatahandler.dll
2006-10-24 04:30:00 276992 ------w- c:\windows\system32\WMPhoto.dll
2006-10-16 08:10:58 23856 ----a-w- c:\windows\system32\spupdsvc.exe

============= FINISH: 8:36:43.42 ===============

Attached Files


Edited by Orange Blossom, 30 January 2010 - 08:37 PM.
Merged topics. ~ OB


#3 syler

syler

  • Malware Response Team
  • 8,150 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Warrington, UK
  • Local time:11:20 PM

Posted 07 February 2010 - 10:42 AM

Hello,

My name is Syler and I will be helping you to solve your Malware issues. If you have since resolved your issues I would appreciate if you
would let me no so I can close this topic, if you still need help please let me no what issues you are still having, in your next reply.

We apologize for the delay in responding to your request for help. Here at Bleeping Computer we get overwhelmed at times, and
we are trying our best to keep up.

  • Download random's system information tool (RSIT) by random/random from here and save it to your desktop.
  • Double click on RSIT.exe to run RSIT.
  • Click Continue at the disclaimer screen.
  • Once it has finished, two logs will open. Please post the contents of both log.txt (<<will be maximized) and info.txt (<<will be minimized)


  1. Please download GMER from one of the following locations, and save it to your desktop:
    • Main Mirror
      This version will download a randomly named file (Recommended)
    • Zip Mirror
      This version will download a zip file you will need to extract first. If you use this mirror, please extract the zip file to your desktop.
  2. Disconnect from the Internet and close all running programs, as this process may crash your computer.
  3. Temporarily disable any real-time active protection so your security program drivers will not conflict with gmer's driver.
  4. Double click on Gmer to run it.
  5. Allow the gmer.sys driver to load if asked.
  6. You may see a rootkit warning window, If you do, click No.
  7. Untick the following boxes on the right side of the Gmer screen.
    Sections
    IAT/EAT
    Files
    Show All
  8. Click on and wait for the scan to finish.
  9. If you see a rootkit warning window, click OK.
  10. Push and save the logfile to your desktop.
  11. Copy and Paste the contents of that file in your next post.



Then please post back here with the following:
  • log.txt
  • info.txt
  • Gmer log

Thanks

unite.jpg


#4 syler

syler

  • Malware Response Team
  • 8,150 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Warrington, UK
  • Local time:11:20 PM

Posted 11 February 2010 - 07:52 PM

Due to the lack of feedback this Topic is closed.

If you need this topic reopened, please request this by sending me a PM
with the address of the thread. This applies only to the original topic starter.

Everyone else please begin a New Topic.

unite.jpg





0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users