Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

hijack this log


  • This topic is locked This topic is locked
2 replies to this topic

#1 dan27music

dan27music

  • Members
  • 19 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Birmingham UK
  • Local time:01:39 AM

Posted 12 June 2010 - 10:25 AM

Hi, I was told I could post my Hijack this Log here, any help in understanding it would be appreciated, thanks.

Dan

Scan saved at 16:12:37, on 12/06/2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Java\jre6\bin\jqs.exe
c:\program files\mcafee.com\agent\mcdetect.exe
c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\HHVcdV5Sys\VC5SecS.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\Program Files\HHVcdV5Sys\VC5Play.exe
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\Program Files\Dell\Media Experience\PCMService.exe
C:\PROGRA~1\mcafee.com\mps\mscifapp.exe
C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
C:\Program Files\eBay\eBay Toolbar2\eBayTBDaemon.exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\DellSupport\DSAgnt.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
C:\Program Files\SlipStream Web Accelerator\slipaccel.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Uniblue\RegistryBooster\registrybooster.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Windows Live\Toolbar\wltuser.exe
C:\Program Files\Trend Micro\RUBotted\TMRUBotted.exe
C:\Program Files\Trend Micro\RUBotted\TMRUBottedTray.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Common Files\eMail ID\IconixService.exe
C:\Program Files\eMail ID\OEAddOn\OEdmn_6.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\system32\msiexec.exe
C:\Documents and Settings\Daniel Rodger\Local Settings\Temporary Internet Files\Content.IE5\NT5EJ9NG\HijackThis[1].exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://uk.msn.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://g.msn.co.uk/0SEENGB/SAOS01?FORM=TOOLBR
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://uk.msn.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://g.msn.co.uk/0SEENGB/SAOS01?FORM=TOOLBR
R3 - URLSearchHook: Freecorder Toolbar - {1392b8d2-5c05-419f-a8f6-b9f15a596612} - C:\Program Files\Freecorder\tbFre1.dll (file missing)
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Freecorder Toolbar - {1392b8d2-5c05-419f-a8f6-b9f15a596612} - C:\Program Files\Freecorder\tbFre1.dll (file missing)
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll
O2 - BHO: Malicious Scripts Scanner - {55EA1964-F5E4-4D6A-B9B2-125B37655FCB} - C:\Documents and Settings\All Users\Application Data\Prevx\pxbho.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
O2 - BHO: IconixBHOClass Class - {761233B6-F228-49E4-8F6B-668499D4E55A} - C:\Program Files\eMail ID\IEAddOn\IconixBHO_42.dll
O2 - BHO: Google Update Helper - {77D7E795-33C5-4323-974D-A2A49AB75517} - C:\Program Files\Google\Update\1.2.131.11\GoopdateBho.dll (file missing)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: UrlHelper Class - {A1123C1A-5D52-4df7-B639-6346165FCD58} - C:\Program Files\BearFlix Applications\BearFlix MediaBar\BearFlixIEHelper.dll (file missing)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.5.5126.1836\swg.dll
O2 - BHO: MSN Toolbar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files\MSN\Toolbar\3.0.1203.0\msneshellx.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: (no name) - {5776A2BC-D803-47F6-9DC0-8344DB8D604C} - (no file)
O3 - Toolbar: eBay Toolbar - {92085AD4-F48A-450D-BD93-B28CC7DF67CE} - C:\Program Files\eBay\eBay Toolbar2\eBayTB.dll
O3 - Toolbar: Freecorder Toolbar - {1392b8d2-5c05-419f-a8f6-b9f15a596612} - C:\Program Files\Freecorder\tbFre1.dll (file missing)
O3 - Toolbar: BearFlix MediaBar - {0388BA0C-C7F1-4E6A-BD7A-B59623F33363} - C:\Program Files\BearFlix Applications\BearFlix MediaBar\BearFlixMediaBar.dll (file missing)
O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O3 - Toolbar: MSN Toolbar - {1E61ED7C-7CB8-49d6-B9E9-AB4C880C8414} - C:\Program Files\MSN\Toolbar\3.0.1203.0\msneshellx.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\mcupdate.exe
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [VC5Player] "C:\Program Files\HHVcdV5Sys\VC5Play.exe"
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
O4 - HKLM\..\Run: [MPSExe] c:\PROGRA~1\mcafee.com\mps\mscifapp.exe /embedding
O4 - HKLM\..\Run: [IntelMeM] C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
O4 - HKLM\..\Run: [eBayToolbar] C:\Program Files\eBay\eBay Toolbar2\eBayTBDaemon.exe
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [AOL Spyware Protection] "C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe"
O4 - HKLM\..\Run: [adiras] adiras.exe
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [dscactivate] "C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe"
O4 - HKLM\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Recordpad] "C:\Program Files\NCH Swift Sound\Recordpad\recordpad.exe" -logon
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [TMRUBottedTray] "C:\Program Files\Trend Micro\RUBotted\TMRUBottedTray.exe"
O4 - HKLM\..\Run: [IconixOEAddOn] "C:\Program Files\eMail ID\OEAddOn\OEdmn_6.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_7 -reboot 1
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [Search Protection] C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe
O4 - HKCU\..\RunOnce: [UniblueRegistryBooster] "C:\Program Files\Uniblue\RegistryBooster\launcher.exe" delay 20000
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: Adobe Media Player.lnk = C:\Program Files\Adobe Media Player\Adobe Media Player.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: AOL 9.0 Tray Icon.lnk = C:\Program Files\AOL 9.0\aoltray.exe
O4 - Global Startup: DSLMON.lnk = C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
O8 - Extra context menu item: &eBay Search - res://C:\Program Files\eBay\eBay Toolbar2\eBayTb.dll/RCSearch.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Google Sidewiki... - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html
O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: (no name) - {400A6CFA-E326-4d61-A90C-9AD75358DC5F} - C:\Program Files\eMail ID\IEAddOn\IconixBHO_42.dll
O9 - Extra 'Tools' menuitem: Email ID Preferences - {400A6CFA-E326-4d61-A90C-9AD75358DC5F} - C:\Program Files\eMail ID\IEAddOn\IconixBHO_42.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {BC3F6B6D-2E49-4603-B028-7411655713F3} - C:\Program Files\eMail ID\IEAddOn\IconixBHO_42.dll
O9 - Extra 'Tools' menuitem: About Email ID - {BC3F6B6D-2E49-4603-B028-7411655713F3} - C:\Program Files\eMail ID\IEAddOn\IconixBHO_42.dll
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.tiscali.co.uk/
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - http://housecall65.trendmicro.com/housecal...ivex/hcImpl.cab
O16 - DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} (EPUImageControl Class) - http://tools.ebayimg.com/eps/wl/activex/eB...l_v1-0-3-30.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by15fd.bay15.hotmail.msn.com/resources/MsnPUpld.cab
O16 - DPF: {5F0C30E4-1E72-4DCC-85E5-57810F1CA97B} (McUpdatePortalFactory Class) - http://www.amiuptodate.com/vsc/bin/1,0,0,9...pdatePortal.cab
O16 - DPF: {A8F2B9BD-A6A0-486A-9744-18920D898429} - http://www.sibelius.com/download/software/...tiveXPlugin.cab
O16 - DPF: {C606BA60-AB76-48B6-96A7-2C4D5C386F70} (PreQualifier Class) - http://www.sc-server1.bt.com/broadband/MotivePreQual.cab
O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} -
O16 - DPF: {E8F628B5-259A-4734-97EE-BA914D7BE941} (Driver Agent ActiveX Control) - http://driveragent.com/files/driveragent.cab
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/iss-loc/...123/mcfscan.cab
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Iconix Update Service (IconixService) - Unknown owner - C:\Program Files\Common Files\eMail ID\IconixService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe
O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: Prevx Agent (PREVXAgent) - Unknown owner - C:\Program Files\Prevx2\PXAgent.exe (file missing)
O23 - Service: Trend Micro RUBotted Service (RUBotted) - Trend Micro Inc. - C:\Program Files\Trend Micro\RUBotted\TMRUBotted.exe
O23 - Service: Virtual CD v5 Security service (VC5SecS) - H+H Software GmbH - C:\Program Files\HHVcdV5Sys\VC5SecS.exe

--
End of file - 16602 bytes

EDIT: Moved from XP to Malware Removal Logs forum ~ Hamluis.


Hello again, I've also posted the DDS file below and attached the 'Attach' file. There are no specific problems with my PC, but it runs a little slowly sometimes and crashes. I've run Spybot and a couple of other spyware killers. It's running ok at present. Thanks for any help. Have a great evening

DDS (Ver_10-03-17.01) - NTFSx86
Run by Daniel Rodger at 17:15:27.90

on 12/06/2010
Internet Explorer: 8.0.6001.18702
Microsoft Windows XP Home Edition

5.1.2600.3.1252.1.1033.18.510.87

[GMT 1:00]

AV: avast! antivirus 4.8.1368 [VPS

100119-0] *On-access scanning

enabled* (Updated)

{7591DB91-41F0-48A3-B128-1A293FD8233

D}
AV: Prevx 2.0 *On-access scanning

disabled* (Updated)

{557C3342-BC52-4508-AC25-4441BDF5C04

C}

============== Running Processes

===============

C:\WINDOWS\system32\svchost -k

DcomLaunch
svchost.exe
C:\Program Files\Windows

Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe -k

netsvcs
svchost.exe
svchost.exe
C:\Program Files\Alwil

Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil

Software\Avast4\ashServ.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
svchost.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd

.exe
C:\WINDOWS\Explorer.EXE
C:\Program

Files\Java\jre6\bin\jqs.exe
c:\program

files\mcafee.com\agent\mcdetect.exe
c:\PROGRA~1\mcafee.com\agent\mctsksh

d.exe
C:\Program Files\Common

Files\Microsoft

Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Microsoft\Search

Enhancement Pack\SeaPort\SeaPort.exe
C:\WINDOWS\system32\svchost.exe -k

imgsvc
C:\Program

Files\HHVcdV5Sys\VC5SecS.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\PROGRA~1\mcafee.com\agent\mcagent

.exe
C:\Program

Files\HHVcdV5Sys\VC5Play.exe
C:\Program Files\Analog

Devices\Core\smax4pnp.exe
C:\Program Files\Dell\Media

Experience\PCMService.exe
C:\PROGRA~1\mcafee.com\mps\mscifapp.

exe
C:\Program Files\Intel\Modem Event

Monitor\IntelMEM.exe
C:\Program Files\eBay\eBay

Toolbar2\eBayTBDaemon.exe
C:\Program

Files\CyberLink\PowerDVD\DVDLauncher

.exe
C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AO

LSP Scheduler.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Windows

Defender\MSASCui.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.

exe
C:\Program Files\Common

Files\Real\Update_OB\realsched.exe
C:\Program Files\Common

Files\Java\Java Update\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program

Files\DellSupport\DSAgnt.exe
C:\Program Files\Windows

Live\Messenger\msnmsgr.exe
C:\Program Files\Spybot - Search &

Destroy\TeaTimer.exe
C:\Program Files\SAGEM\SAGEM F@st

800-840\dslmon.exe
C:\Program Files\SlipStream Web

Accelerator\slipaccel.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program

Files\Uniblue\RegistryBooster\regist

rybooster.exe
C:\Program Files\Internet

Explorer\IEXPLORE.EXE
C:\Program Files\Internet

Explorer\IEXPLORE.EXE
C:\Program Files\Windows

Live\Toolbar\wltuser.exe
C:\Program Files\Trend

Micro\RUBotted\TMRUBotted.exe
C:\Program Files\Trend

Micro\RUBotted\TMRUBottedTray.exe
C:\Program Files\Internet

Explorer\IEXPLORE.EXE
C:\Program Files\Common Files\eMail

ID\IconixService.exe
C:\Program Files\eMail

ID\OEAddOn\OEdmn_6.exe
C:\Program Files\Internet

Explorer\IEXPLORE.EXE
C:\Program Files\Internet

Explorer\IEXPLORE.EXE
C:\Documents and Settings\Daniel

Rodger\Local Settings\Temporary

Internet

Files\Content.IE5\ZP3ZY72T\dds[1].sc

r

============== Pseudo HJT Report

===============

uSearch Page =

hxxp://g.msn.co.uk/0SEENGB/SAOS01?FO

RM=TOOLBR
uSearchMigratedDefaultURL =

hxxp://search.live.com/results.aspx?

q={searchTerms}&src={referrer:source

?}
uSearchURL,(Default) =

hxxp://g.msn.co.uk/0SEENGB/SAOS01?FO

RM=TOOLBR
uURLSearchHooks: Freecorder Toolbar:

{1392b8d2-5c05-419f-a8f6-b9f15a59661

2} - c:\program

files\freecorder\tbFre1.dll
BHO:

{02478D38-C3F9-4efb-9B51-7695ECA0567

0} - No File
BHO: Adobe PDF Reader Link Helper:

{06849e9f-c8d7-4d59-b87d-784b7d6be0b

3} - c:\program files\common

files\adobe\acrobat\activex\AcroIEHe

lper.dll
BHO: Freecorder Toolbar:

{1392b8d2-5c05-419f-a8f6-b9f15a59661

2} - c:\program

files\freecorder\tbFre1.dll
BHO: Adobe PDF Link Helper:

{18df081c-e8ad-4283-a596-fa578c2ebdc

3} - c:\program files\common

files\adobe\acrobat\activex\AcroIEHe

lperShim.dll
BHO: RealPlayer Download and Record

Plugin for Internet Explorer:

{3049c3e9-b461-4bc5-8870-4c09146192c

a} - c:\documents and settings\all

users\application

data\real\realplayer\browserrecordpl

ugin\ie\rpbrowserrecordplugin.dll
BHO: URLDetector Class:

{55ea1964-f5e4-4d6a-b9b2-125b37655fc

b} - c:\documents and settings\all

users\application

data\prevx\pxbho.dll
BHO:

{5C255C8A-E604-49b4-9D64-90988571CEC

B} - No File
BHO: Search Helper:

{6ebf7485-159f-4bff-a14f-b9e3aac4465

b} - c:\program

files\microsoft\search enhancement

pack\search

helper\SEPsearchhelperie.dll
BHO: IconixBHOClass Class:

{761233b6-f228-49e4-8f6b-668499d4e55

a} - c:\program files\email

id\ieaddon\IconixBHO_42.dll
BHO: Google Update Helper:

{77d7e795-33c5-4323-974d-a2a49ab7551

7} - c:\program

files\google\update\1.2.131.11\Goopd

ateBho.dll
BHO: Windows Live Sign-in Helper:

{9030d464-4c02-4abf-8ecc-5164760863c

6} - c:\program files\common

files\microsoft shared\windows

live\WindowsLiveLogin.dll
BHO: UrlHelper Class:

{a1123c1a-5d52-4df7-b639-6346165fcd5

8} - c:\program files\bearflix

applications\bearflix

mediabar\BearFlixIEHelper.dll
BHO: Google Toolbar Helper:

{aa58ed58-01dd-4d91-8333-cf10577473f

7} - c:\program files\google\google

toolbar\GoogleToolbar_32.dll
BHO: Google Toolbar Notifier BHO:

{af69de43-7d58-4638-b6fa-ce66b5ad205

d} - c:\program

files\google\googletoolbarnotifier\5

.5.5126.1836\swg.dll
BHO: MSN Toolbar Helper:

{d2ce3e00-f94a-4740-988e-03dc2f38c34

f} - c:\program

files\msn\toolbar\3.0.1203.0\msneshe

llx.dll
BHO: Java™ Plug-In 2 SSV Helper:

{dbc80044-a445-435b-bc74-9c25c1c588a

9} - c:\program

files\java\jre6\bin\jp2ssv.dll
BHO: Windows Live Toolbar Helper:

{e15a8dc0-8516-42a1-81ea-dc94ec1acf1

0} - c:\program files\windows

live\toolbar\wltcore.dll
BHO: JQSIEStartDetectorImpl Class:

{e7e6f031-17ce-4c07-bc86-eabfe594f69

c} - c:\program

files\java\jre6\lib\deploy\jqs\ie\jq

s_plugin.dll
TB:

{5776A2BC-D803-47F6-9DC0-8344DB8D604

C} - No File
TB: eBay Toolbar:

{92085ad4-f48a-450d-bd93-b28cc7df67c

e} - c:\program files\ebay\ebay

toolbar2\eBayTB.dll
TB: Freecorder Toolbar:

{1392b8d2-5c05-419f-a8f6-b9f15a59661

2} - c:\program

files\freecorder\tbFre1.dll
TB: BearFlix MediaBar:

{0388ba0c-c7f1-4e6a-bd7a-b59623f3336

3} - c:\program files\bearflix

applications\bearflix

mediabar\BearFlixMediaBar.dll
TB: &Windows Live Toolbar:

{21fa44ef-376d-4d53-9b0f-8a89d322906

8} - c:\program files\windows

live\toolbar\wltcore.dll
TB: MSN Toolbar:

{1e61ed7c-7cb8-49d6-b9e9-ab4c880c841

4} - c:\program

files\msn\toolbar\3.0.1203.0\msneshe

llx.dll
TB: Google Toolbar:

{2318c2b1-4965-11d4-9b18-009027a5cd4

f} - c:\program files\google\google

toolbar\GoogleToolbar_32.dll
TB:

{EF99BD32-C1FB-11D2-892F-0090271D4F8

8} - No File
TB:

{BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D

0} - No File
TB:

{604BC32A-9680-40D1-9AC6-E06B23A1BA4

C} - No File
uRun: [ctfmon.exe]

c:\windows\system32\ctfmon.exe
uRun: [DellSupport] "c:\program

files\dellsupport\DSAgnt.exe"

/startup
uRun: [updateMgr] "c:\program

files\adobe\acrobat

7.0\reader\AdobeUpdateManager.exe"

AcRdB7_0_7 -reboot 1
uRun: [MsnMsgr] "c:\program

files\windows

live\messenger\msnmsgr.exe"

/background
uRun: [DellSupportCenter]

"c:\program files\dell support

center\bin\sprtcmd.exe" /P

DellSupportCenter
uRun: [SpybotSD TeaTimer] c:\program

files\spybot - search &

destroy\TeaTimer.exe
uRun: [Search Protection] c:\program

files\yahoo!\search

protection\SearchProtection.exe
uRunOnce: [UniblueRegistryBooster]

"c:\program

files\uniblue\registrybooster\launch

er.exe" delay 20000
mRun: [dla]

c:\windows\system32\dla\tfswctrl.exe
mRun: [MCUpdateExe]

c:\progra~1\mcafee.com\agent\mcupdat

e.exe
mRun: [MCAgentExe]

c:\progra~1\mcafee.com\agent\mcagent

.exe
mRun: [VC5Player] "c:\program

files\hhvcdv5sys\VC5Play.exe"
mRun: [UpdateManager] "c:\program

files\common files\sonic\update

manager\sgtray.exe" /r
mRun: [SoundMAXPnP] c:\program

files\analog

devices\core\smax4pnp.exe
mRun: [QuickTime Task] "c:\program

files\quicktime\qttask.exe"

-atboottime
mRun: [PCMService] "c:\program

files\dell\media

experience\PCMService.exe"
mRun: [MPSExe]

c:\progra~1\mcafee.com\mps\mscifapp.

exe /embedding
mRun: [IntelMeM] c:\program

files\intel\modem event

monitor\IntelMEM.exe
mRun: [eBayToolbar] c:\program

files\ebay\ebay

toolbar2\eBayTBDaemon.exe
mRun: [DVDLauncher] "c:\program

files\cyberlink\powerdvd\DVDLauncher

.exe"
mRun: [AOL Spyware Protection]

"c:\progra~1\common~1\aol\aolspy~1\A

OLSP Scheduler.exe"
mRun: [adiras] adiras.exe
mRun: [igfxtray]

c:\windows\system32\igfxtray.exe
mRun: [igfxhkcmd]

c:\windows\system32\hkcmd.exe
mRun: [igfxpers]

c:\windows\system32\igfxpers.exe
mRun: [Windows Defender] "c:\program

files\windows defender\MSASCui.exe"

-hide
mRun: [dscactivate] "c:\program

files\dell support

center\gs_agent\custom\dsca.exe"
mRun: [DellSupportCenter]

"c:\program files\dell support

center\bin\sprtcmd.exe" /P

DellSupportCenter
mRun: [Adobe Reader Speed Launcher]

"c:\program files\adobe\reader

9.0\reader\Reader_sl.exe"
mRun: [avast!]

c:\progra~1\alwils~1\avast4\ashDisp.

exe
mRun: [TkBellExe] "c:\program

files\common

files\real\update_ob\realsched.exe"

-osboot
mRun: [Recordpad] "c:\program

files\nch swift

sound\recordpad\recordpad.exe"

-logon
mRun: [SunJavaUpdateSched]

"c:\program files\common

files\java\java update\jusched.exe"
mRun: [TMRUBottedTray] "c:\program

files\trend

micro\rubotted\TMRUBottedTray.exe"
mRun: [IconixOEAddOn] "c:\program

files\email id\oeaddon\OEdmn_6.exe"
dRun: [CTFMON.EXE]

c:\windows\system32\CTFMON.EXE
dRun: [DWQueuedReporting]

"c:\progra~1\common~1\micros~1\dw\dw

trig20.exe" -t
StartupFolder:

c:\docume~1\daniel~1\startm~1\progra

ms\startup\adobem~1.lnk - c:\program

files\adobe media player\Adobe Media

Player.exe
StartupFolder:

c:\docume~1\alluse~1\startm~1\progra

ms\startup\adober~1.lnk - c:\program

files\adobe\acrobat

7.0\reader\reader_sl.exe
StartupFolder:

c:\docume~1\alluse~1\startm~1\progra

ms\startup\aol90t~1.lnk - c:\program

files\aol 9.0\aoltray.exe
StartupFolder:

c:\docume~1\alluse~1\startm~1\progra

ms\startup\dslmon.lnk - c:\program

files\sagem\sagem f@st

800-840\dslmon.exe
IE: &eBay Search - c:\program

files\ebay\ebay

toolbar2\eBayTb.dll/RCSearch.html
IE: E&xport to Microsoft Excel -

c:\progra~1\micros~2\office11\EXCEL.

EXE/3000
IE: Google Sidewiki... - c:\program

files\google\google

toolbar\component\GoogleToolbarDynam

ic_mui_en_96D6FF0C6D236BF8.dll/cmsid

ewiki.html
IE:

{CD67F990-D8E9-11d2-98FE-00C0F0318AF

E}
IE:

{e2e2dd38-d088-4134-82b7-f2ba3849658

3} - %windir%\Network

Diagnostic\xpnetdiag.exe
IE:

{FB5F1910-F110-11d2-BB9E-00C04F79568

3} - c:\program

files\messenger\msmsgs.exe
IE:

{219C3416-8CB2-491a-A3C7-D9FCDDC9D60

0} -

{5F7B1267-94A9-47F5-98DB-E99415F33AE

C} - c:\program files\windows

live\writer\WriterBrowserExtension.d

ll
IE:

{400A6CFA-E326-4d61-A90C-9AD75358DC5

F} -

{44E212AB-13EA-4CA4-BE65-197FBA17041

2} - c:\program files\email

id\ieaddon\IconixBHO_42.dll
IE:

{92780B25-18CC-41C8-B9BE-3C9C571A826

3} -

{FF059E31-CC5A-4E2E-BF3B-96E929D6550

3} -

c:\progra~1\micros~2\office11\REFIEB

AR.DLL
IE:

{BC3F6B6D-2E49-4603-B028-7411655713F

3} -

{0CC2F28D-D415-4FC6-A2E4-54B4D983609

A} - c:\program files\email

id\ieaddon\IconixBHO_42.dll
LSP: c:\windows\system32\mclsp.dll
DPF:

{0000000A-0000-0010-8000-00AA00389B7

1} -

hxxp://download.microsoft.com/downlo

ad/d/4/4/d446e8a9-3a86-4b59-bb19-f5b

d11b40367/wmavax.CAB
DPF:

{166B1BCA-3F9C-11CF-8075-44455354000

0} -

hxxp://fpdownload.macromedia.com/get

/shockwave/cabs/director/sw.cab
DPF:

{17492023-C23A-453E-A040-C7C580BBF70

0} -

hxxp://download.microsoft.com/downlo

ad/9/b/d/9bdc68ef-6a9f-4505-8fb8-d0d

2d160e512/LegitCheckControl.cab
DPF:

{215B8138-A3CF-44C5-803F-8226143CFC0

A} -

hxxp://housecall65.trendmicro.com/ho

usecall/applet/html/native/x86/win32

/activex/hcImpl.cab
DPF:

{33564D57-0000-0010-8000-00AA00389B7

1} -

hxxp://download.microsoft.com/downlo

ad/F/6/E/F6E491A6-77E1-4E20-9F5F-949

01338C922/wmv9VCM.CAB
DPF:

{4C39376E-FA9D-4349-BACC-D305C1750EF

3} -

hxxp://tools.ebayimg.com/eps/wl/acti

vex/eBay_Enhanced_Picture_Control_v1

-0-3-30.cab
DPF:

{4F1E5B1A-2A80-42CA-8532-2D05CB95953

7} -

hxxp://by15fd.bay15.hotmail.msn.com/

resources/MsnPUpld.cab
DPF:

{5F0C30E4-1E72-4DCC-85E5-57810F1CA97

B} -

hxxp://www.amiuptodate.com/vsc/bin/1

,0,0,9/McUpdatePortal.cab
DPF:

{8AD9C840-044E-11D1-B3E9-00805F499D9

3} -

hxxp://java.sun.com/update/1.6.0/jin

stall-1_6_0_20-windows-i586.cab
DPF:

{8FFBE65D-2C9C-4669-84BD-5829DC0B603

C} -

hxxp://fpdownload.macromedia.com/get

/flashplayer/current/polarbear/ultra

shim.cab
DPF:

{A8F2B9BD-A6A0-486A-9744-18920D89842

9} -

hxxp://www.sibelius.com/download/sof

tware/win/ActiveXPlugin.cab
DPF:

{C606BA60-AB76-48B6-96A7-2C4D5C386F7

0} -

hxxp://www.sc-server1.bt.com/broadba

nd/MotivePreQual.cab
DPF:

{CAFEEFAC-0014-0002-0003-ABCDEFFEDCB

A} -

hxxp://java.sun.com/update/1.4.2/jin

stall-1_4_2_03-windows-i586.cab
DPF:

{CAFEEFAC-0016-0000-0020-ABCDEFFEDCB

A} -

hxxp://java.sun.com/update/1.6.0/jin

stall-1_6_0_20-windows-i586.cab
DPF:

{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCB

A} -

hxxp://java.sun.com/update/1.6.0/jin

stall-1_6_0_20-windows-i586.cab
DPF:

{CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA

7}
DPF:

{E8F628B5-259A-4734-97EE-BA914D7BE94

1} -

hxxp://driveragent.com/files/drivera

gent.cab
DPF:

{EF791A6B-FC12-4C68-99EF-FB9E207A39E

6} -

hxxp://download.mcafee.com/molbin/is

s-loc/mcfscan/2,2,0,5123/mcfscan.cab
Filter:

application/x-internet-signup -

{A173B69A-1F9B-4823-9FDA-412F641E65D

6} - c:\program

files\tiscali\tiscali

internet\dlls\tiscalifilter.dll
Notify: igfxcui - igfxdev.dll
SSODL: WPDShServiceObj -

{AAA288BA-9A4C-45B0-95D7-94D524869DB

5} -

c:\windows\system32\WPDShServiceObj.

dll
SEH: Microsoft AntiMalware

ShellExecuteHook:

{091eb208-39dd-417d-a5dd-7e2c2d8fb9c

b} -

c:\progra~1\window~4\MpShHook.dll
Hosts: 127.0.0.1

www.spywareinfo.com

============= SERVICES / DRIVERS

===============

R1 aswSP;avast! Self

Protection;c:\windows\system32\drive

rs\aswSP.sys [2009-8-25 114768]
R1 PREVXTdi;PREVX TDI

filter;c:\windows\system32\drivers\p

xtdi.sys [2007-7-24 27784]
R1

vbev5mp;vbev5mp;c:\windows\system32\

drivers\vbev5mp.sys [2005-11-29

57008]
R2

aswFsBlk;aswFsBlk;c:\windows\system3

2\drivers\aswFsBlk.sys [2009-8-25

20560]
R2 avast! Antivirus;avast!

Antivirus;c:\program files\alwil

software\avast4\ashServ.exe

[2009-8-25 138680]
R2 IconixService;Iconix Update

Service;c:\program files\common

files\email id\IconixService.exe

[2010-6-12 283992]
R2 McDetect.exe;McAfee WSC

Integration;c:\program

files\mcafee.com\agent\Mcdetect.exe

[2005-8-22 126976]
R2 McTskshd.exe;McAfee Task

Scheduler;c:\progra~1\mcafee.com\age

nt\mctskshd.exe [2005-8-22 122368]
R2 RUBotted;Trend Micro RUBotted

Service;c:\program files\trend

micro\rubotted\TMRUBotted.exe

[2010-6-12 582992]
R2 WinDefend;Windows

Defender;c:\program files\windows

defender\MsMpEng.exe [2006-11-3

13592]
R3

TMPassthruMP;TMPassthruMP;c:\windows

\system32\drivers\TMPassthru.sys

[2010-6-12 206608]
S2 gupdate;Google Update Service

(gupdate);c:\program

files\google\update\GoogleUpdate.exe

[2010-3-10 135664]
S3 avast! Mail Scanner;avast! Mail

Scanner;c:\program files\alwil

software\avast4\ashMaiSv.exe

[2009-8-25 254040]
S3 avast! Web Scanner;avast! Web

Scanner;c:\program files\alwil

software\avast4\ashWebSv.exe

[2009-8-25 352920]
S3 JL2005;JL2005A

Camera;c:\windows\system32\drivers\t

oywdm.sys [2004-9-20 71272]
S3 mcupdmgr.exe;McAfee

SecurityCenter Update

Manager;c:\progra~1\mcafee.com\agent

\mcupdmgr.exe [2005-4-24 245760]
S3 PREVXEmulator;PREVX Emulator

driver;c:\windows\system32\drivers\P

xEmu.sys [2007-7-24 107784]
S3 TMPassthru;Trend Micro Passthru

Ndis

Service;c:\windows\system32\drivers\

TMPassthru.sys [2010-6-12 206608]

=============== Created Last 30

================

2010-06-12 15:06:13 0

d-----w-

c:\docume~1\daniel~1\applic~1\eMail

ID
2010-06-12 15:06:13 0

d-----w-

c:\docume~1\alluse~1\applic~1\eMail

ID
2010-06-12 15:04:59 0

d-----w- c:\program

files\common files\eMail ID
2010-06-12 15:04:41 0

d-----w- c:\program

files\eMail ID
2010-06-12 14:54:02 206608

----a-w-

c:\windows\system32\drivers\TMPassth

ru.sys
2010-06-12 14:53:27 0

d-----w- c:\program

files\Trend Micro
2010-06-12 14:21:49 0

d-----w- c:\program

files\Uniblue
2010-06-12 11:43:55 0

d-----w-

c:\windows\system32\wbem\Repository

==================== Find3M

====================

2010-05-12 10:21:16 221568

------w-

c:\windows\system32\MpSigStub.exe
2010-04-26 00:08:06 152904

----a-w-

c:\windows\system32\vghd.scr
2010-04-12 16:29:19 411368

----a-w-

c:\windows\system32\deployJava1.dll
2005-11-29 18:30:32 774144

-c--a-w- c:\program

files\RngInterstitial.dll
2008-08-20 08:32:23 32768

-csha-w-

c:\windows\system32\config\systempro

file\local

settings\history\history.ie5\mshist0

12008082020080821\index.dat

============= FINISH: 17:17:03.68

===============

Attached Files


Edited by dan27music, 12 June 2010 - 11:38 AM.


BC AdBot (Login to Remove)

 


#2 etavares

etavares

    Bleepin' Remover


  • Malware Response Team
  • 15,514 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:08:39 PM

Posted 16 June 2010 - 05:37 PM

Hello and welcome to Bleeping Computer

We apologize for the delay in responding to your request for help. Here at Bleeping Computer we get overwhelmed at times, and we are trying our best to keep up. Please note that your topic was not intentionally overlooked. Our mission is to help everyone in need, but sometimes it takes just a little longer to get to every request for help. No one is ignored here.

If you have since resolved the original problem you were having, we would appreciate you letting us know. If not please perform the following steps below so we can have a look at the current condition of your machine.

If you have not done so, include a clear description of the problems you're having, along with any steps you may have performed so far.

Please refrain from running tools or applying updates other than those we suggest while we are cleaning up your computer. The reason for this is so we know what is going on with the machine at any time. Some programs can interfere with others and hamper the recovery process. Please also continue to work with me until I give you the all clear. Even if your computer appears to act better, you may still be infected.

Even if you have already provided information about your PC, we need a new log to see what has changed since you originally posted your problem.

Once we start working together, please reply back within 3 days or this thread may be closed so we can help others who are waiting.

We need to create an OTL report,
  • Please download OTL from this link.
  • Save it to your desktop.
  • Double click on the icon on your desktop.
  • Click the "Scan All Users" checkbox.
  • Under the Custom Scan box paste this in:

    netsvcs
    msconfig
    activex
    drivers32
    %systemroot%\system32\*.dll /lockedfiles
    %systemroot%\Tasks\*.job /lockedfiles
    %SYSTEMDRIVE%\*.exe
    /md5start
    eventlog.dll
    scecli.dll
    netlogon.dll
    cngaudit.dll
    sceclt.dll
    ntelogon.dll
    logevent.dll
    iaStor.sys
    nvstor.sys
    atapi.sys
    IdeChnDr.sys
    viasraid.sys
    AGP440.sys
    vaxscsi.sys
    nvatabus.sys
    viamraid.sys
    nvata.sys
    nvgts.sys
    iastorv.sys
    ViPrt.sys
    eNetHook.dll
    ahcix86.sys
    KR10N.sys
    nvstor32
    ahcix86s.sys
    nvrd32.sys
    /md5stop
    %systemroot%\*. /mp /s
    CREATERESTOREPOINT

  • Click the Quick Scan button.
  • The scan should take a few minutes.
  • Please copy and paste both logs in your reply.

We also need a new log from the GMER anti-rootkit scanner. Please first disable any CD emulation programs using the steps found in this topic:

Why we request you disable CD Emulation when receiving Malware Removal Advice

Then create another GMER log and post it as an attachment to the reply where you post your new OTL log. Instructions on how to properly create a GMER log can be found here:

How to create a GMER log


In your reply, please post both OTL logs and the GMER log.

PS> Please turn OFF wordwrap in notepad before copy and pasting in your reply.


If I don't respond within 2 days, please feel free to PM me.
Please don't ask for help via PM. The forums are there for a reason. Please post in the forums so others may benefit as well.

Posted Image
Unified Network of Instructors and Trusted Eliminators
 


#3 etavares

etavares

    Bleepin' Remover


  • Malware Response Team
  • 15,514 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:08:39 PM

Posted 21 June 2010 - 06:04 PM

Due to the lack of feedback, this Topic is closed.

If you need this topic reopened, please request this by sending the moderating team
a PM with the address of the thread. This applies only to the original topic starter.

Everyone else please begin a New Topic.


If I don't respond within 2 days, please feel free to PM me.
Please don't ask for help via PM. The forums are there for a reason. Please post in the forums so others may benefit as well.

Posted Image
Unified Network of Instructors and Trusted Eliminators
 





0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users